A security analyst needs to assess internal enterprise workstations for missing operating system patches and local configuration weaknesses without sending administrative credentials across the network during the scan. Which of the following scanning methods should the analyst deploy to achieve this goal?
- Agent-based vulnerability scanningAnswer
- BNon-credentialed network vulnerability scanning
- CPassive network traffic monitoring
- DWeb application vulnerability scanning
Answer
Agent-based vulnerability scanning provides direct host-level visibility into missing patches and local configurations without requiring administrative credentials over the network.
Agent-based scanning installs a lightweight agent directly on target endpoints. Because the agent runs locally within the operating system, it can thoroughly audit installed updates, local registry keys, and software configurations without transmitting domain or host credentials over the network.
Step-by-Step Solution
Key Concept
Agent-based vs. network-based vulnerability scanning