A security technician needs to conduct an internal vulnerability scan across local workstations to accurately audit operating system patch levels and local registry configurations while minimizing network traffic overhead. Which of the following scan methods should the technician select?
- Credentialed vulnerability scanAnswer
- BNon-credentialed vulnerability scan
- CIntrusive penetration test
- DInline web application firewall assessment
Answer
Credentialed vulnerability scan
Credentialed vulnerability scans authenticate directly to the target system using valid user or service credentials. This enables the scanner to inspect internal file versions, installed updates, and registry configurations directly on the host, producing highly accurate results with minimal network traffic.
Step-by-Step Solution
Key Concept
Credentialed vs. Non-Credentialed Vulnerability Scanning