Match each vulnerability scanning approach to its corresponding operational characteristic or primary benefit.
- Credentialed ScanProvides internal software inventory and missing patch details with low system impact
- Non-Credentialed ScanSimulates an external attacker's perspective without insider access privileges
- Passive ScanMonitors network traffic silently without sending probes or generating active network traffic
- Agent-Based ScanContinuously assesses mobile or off-network endpoints even when disconnected from the corporate VPN
Answer
Credentialed Scan pairs with internal software inventory and patch details; Non-Credentialed Scan pairs with simulating an external attacker's perspective; Passive Scan pairs with silently monitoring network traffic without probes; Agent-Based Scan pairs with assessing off-network endpoints continuously.
Vulnerability assessment modalities differ fundamentally by access rights, deployment model, and network footprint: credentialed scans perform local patch audits, non-credentialed scans map external surface vulnerabilities, passive scans monitor packet headers without sending probes, and agent-based scans gather host posture locally on mobile devices.
Step-by-Step Solution
Key Concept
Vulnerability Scanning Types and Deployment Methodologies