nerdexam
EC-Council

312-50V12 · Question #121

An organization is performing a vulnerability assessment for mitigating threats. James, a pen tester, scanned the organization by building an inventory of the protocols found on the organization's mac

The correct answer is D. Inference-based assessment. There are four types of vulnerability assessment solutions: product-based solutions, service- based solutions, tree-based assessment, and inference-based assessment. In an inference-based assessment, scanning starts by building an inventory of the protocols found on the machine.

Submitted by miguelv· Mar 4, 2026System Hacking Phases and Attack Techniques

Question

An organization is performing a vulnerability assessment for mitigating threats. James, a pen tester, scanned the organization by building an inventory of the protocols found on the organization's machines to detect which ports are attached to services such as an email server, a web server, or a database server. After identifying the services, he selected the vulnerabilities on each machine and started executing only the relevant tests. What is the type of vulnerability assessment solution that James employed in the above scenario?

Options

  • AService-based solutions
  • BProduct-based solutions
  • CTree-based assessment
  • DInference-based assessment

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    12% (3)
  • C
    4% (1)
  • D
    80% (20)

Explanation

There are four types of vulnerability assessment solutions: product-based solutions, service- based solutions, tree-based assessment, and inference-based assessment. In an inference-based assessment, scanning starts by building an inventory of the protocols found on the machine. After finding a protocol, the scanning process starts to detect which ports are attached to services, such as an email server, web server, or database server. After finding services, it selects vulnerabilities on each machine and starts to execute only those relevant

Topics

#vulnerability assessment#inference-based assessment#service-based scanning#port scanning

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice