A security administrator is planning a routine security evaluation of internal server infrastructure. Which of the following are distinct operational advantages of conducting a credentialed vulnerability scan rather than a non-credentialed network scan? (Select TWO.)
- Identification of missing local software patches and operating system updatesAnswer
- Lower rate of false positives due to direct host configuration queryingAnswer
- CAutomatic modification of network firewall rules to remediate discovered software flaws
- DReclassification of detective scanning mechanisms into active preventive network access controls
Answer
Credentialed vulnerability scans provide direct inspection of missing local patches and system configurations while significantly reducing false positives through direct host querying.
Credentialed vulnerability scans log into target systems to directly audit local file versions, installed security updates, and configuration files. This internal visibility enables precise patch verification and dramatically reduces false positives compared to unauthenticated network probing.
Step-by-Step Solution
Key Concept
Credentialed vs. Non-Credentialed Vulnerability Scanning