nerdexam
EC-Council

312-50V12 · Question #195

In the process of implementing a network vulnerability assessment strategy for a tech company, the security analyst is confronted with the following scenarios: 1) A legacy application is discovered…

The correct answer is A. Vulnerability scanning software cannot define the impact of an identified vulnerability on different. Vulnerability scanning software excels at identifying technical flaws but inherently struggles to assess the broader business impact or organizational risk associated with those identified vulnerabilities.

Submitted by emma.c· Mar 4, 2026System Hacking Phases and Attack Techniques

Question

In the process of implementing a network vulnerability assessment strategy for a tech company, the security analyst is confronted with the following scenarios: 1) A legacy application is discovered on the network, which no longer receives updates from the vendor. 2) Several systems in the network are found running outdated versions of web browsers prone to distributed attacks. 3) The network firewall has been configured using default settings and passwords. 4) Certain TCP/IP protocols used in the organization are inherently insecure. The security analyst decides to use vulnerability scanning software. Which of the following limitations of vulnerability assessment should the analyst be most cautious about in this context?

Options

  • AVulnerability scanning software cannot define the impact of an identified vulnerability on different
  • BVulnerability scanning software is not immune to software engineering flaws that might lead to
  • CVulnerability scanning software is limited in its ability to detect vulnerabilities at a given point in
  • DVulnerability scanning software is limited in its ability to perform live tests on web applications to

How the community answered

(30 responses)
  • A
    80% (24)
  • B
    10% (3)
  • C
    3% (1)
  • D
    7% (2)

Why each option

Vulnerability scanning software excels at identifying technical flaws but inherently struggles to assess the broader business impact or organizational risk associated with those identified vulnerabilities.

AVulnerability scanning software cannot define the impact of an identified vulnerability on differentCorrect

Vulnerability scanning software primarily identifies technical weaknesses (like outdated software, default configurations, or insecure protocols) but lacks the contextual understanding of an organization's specific assets, business processes, and their criticality to accurately define the potential operational, financial, or reputational impact of an identified vulnerability. This crucial step requires human analysis and organizational context beyond the scanner's capabilities to prioritize remediation effectively.

BVulnerability scanning software is not immune to software engineering flaws that might lead to

While true that all software can have flaws, this describes a general risk of software engineering and not a specific limitation regarding the scope or output of vulnerability assessment in the context of defining impact.

CVulnerability scanning software is limited in its ability to detect vulnerabilities at a given point in

This describes a limitation related to the frequency or scheduling of scans, not the scanner's inherent ability to interpret and define the business impact of vulnerabilities it detects.

DVulnerability scanning software is limited in its ability to perform live tests on web applications to

While many general vulnerability scanners might have limitations in deep, live web application testing (which is often handled by specialized DAST tools), this is a limitation in detection *methodology*, not in the post-detection assessment of the *impact* of already identified vulnerabilities, which is the core concern of the question.

Concept tested: Limitations of vulnerability scanning in risk assessment

Source: https://learn.microsoft.com/en-us/training/modules/implement-vulnerability-management/4-prioritize-remediation-efforts

Topics

#vulnerability assessment#vulnerability scanning#scanner limitations#impact analysis

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice