A systems administrator needs to assess internal enterprise servers for missing operating system patches and local security misconfigurations. To obtain accurate, detailed host inspection results while minimizing false positives and network noise, the administrator must avoid attempting any actual system exploitation. Which of the following scanning approaches best satisfies these requirements?
- Credentialed vulnerability scanCevap
- BNon-credentialed network scan
- CIntrusive penetration test
- DInline firewall packet analysis
Cevap
Credentialed vulnerability scan
The option selecting a credentialed vulnerability scan is correct because providing valid login credentials allows the scanner to log into the host and examine local settings, registry keys, and missing system updates directly. This yields precise findings with minimal false positives and zero risk of causing service outages through exploit execution.
Adım Adım Çözüm
Anahtar Kavram
Credentialed vs. Non-Credentialed Vulnerability Scanning
Tahmini Süre:45s