Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementMedium

A security consultant is asked to perform a vulnerability assessment for a client's internal network. The client explicitly states that the assessment must be conducted from the perspective of an authenticated user with standard domain user privileges to identify vulnerabilities accessible to a typical employee. Which type of vulnerability scanning approach should the consultant primarily utilize?

  1. AWeb application scan
  2. BInternal, credentialed scan
  3. CCloud security posture management (CSPM) scan
  4. DExternal, uncredentialed scan
Show answer & explanation

Correct answer: B. Internal, credentialed scan

An internal, credentialed scan with standard domain user privileges directly addresses the client's requirement to assess vulnerabilities from the perspective of an authenticated, typical employee within the internal network.

Why the other options are wrong

  • A. This focuses specifically on web applications, not the general internal network or user perspective.
  • C. CSPM focuses on cloud environments and configurations, not internal network host vulnerabilities from a user's perspective.
  • D. This simulates an external attacker with no credentials, not an internal authenticated user.

Credentialed Scan

A vulnerability scan performed with authenticated access to target systems, allowing for deeper and more accurate vulnerability identification.

  • Provides a more thorough assessment than uncredentialed scans.
  • Can uncover misconfigurations and patch levels not visible externally.
  • Requires valid login credentials for target systems.

Memory trick: Credentialed scans are like 'unlocking the door' to see inside.

More Vulnerability Management questions