An administrator needs to perform a vulnerability scan on internal servers to accurately detect missing software patches without installing host software agents. Which of the following scanning methods should the administrator use?
- Credentialed vulnerability scanAnswer
- BNon-credentialed vulnerability scan
- CPassive network traffic inspection
- DInline honeypot service deployment
Answer
Credentialed vulnerability scan
A credentialed vulnerability scan allows the scanner to log into target hosts using valid permissions to inspect installed applications, registry keys, and operating system patch levels directly. This provides high accuracy and low false-positive rates without requiring permanent agent installations.
Step-by-Step Solution
Key Concept
Credentialed vs. Non-Credentialed Vulnerability Scanning
Estimated Time:1m 0s