nerdexam
EC-Council

312-50V13 · Question #522

In the process of implementing a network vulnerability assessment strategy for a tech company, the security analyst is confronted with the following scenarios: 1) A legacy application is discovered…

The correct answer is D. Vulnerability scanning software is not immune to software engineering flaws that might lead to. Explanation Option D is correct because vulnerability scanning software itself can contain software engineering flaws, bugs, or coding errors that may cause it to miss vulnerabilities, produce false results, or even introduce new security issues - this is especially critical…

Submitted by cyberguy42· Mar 6, 2026Vulnerability Analysis

Question

In the process of implementing a network vulnerability assessment strategy for a tech company, the security analyst is confronted with the following scenarios: 1) A legacy application is discovered on the network, which no longer receives updates from the vendor. 2) Several systems in the network are found running outdated versions of web browsers prone to distributed attacks. 3) The network firewall has been configured using default settings and passwords. 4) Certain TCP/IP protocols used in the organization are inherently insecure. The security analyst decides to use vulnerability scanning software. Which of the following limitations of vulnerability assessment should the analyst be most cautious about in this context?

Options

  • AVulnerability scanning software is limited in its ability to perform live tests on web applications to
  • BVulnerability scanning software cannot define the impact of an identified vulnerability on different
  • CVulnerability scanning software is limited in its ability to detect vulnerabilities at a given point in
  • DVulnerability scanning software is not immune to software engineering flaws that might lead to

How the community answered

(60 responses)
  • A
    7% (4)
  • B
    5% (3)
  • C
    18% (11)
  • D
    70% (42)

Explanation

Explanation

Option D is correct because vulnerability scanning software itself can contain software engineering flaws, bugs, or coding errors that may cause it to miss vulnerabilities, produce false results, or even introduce new security issues - this is especially critical given the four scenarios described, where multiple complex vulnerability types (legacy software, outdated browsers, default configurations, and insecure protocols) require accurate detection across different contexts. A flawed scanning tool could provide a false sense of security across all four scenarios simultaneously.

Why the distractors are wrong:

  • Option A is incorrect because many modern vulnerability scanners can perform live tests on web applications, so this is not the most significant limitation in this context.
  • Option B is incorrect because while impact assessment has nuances, most vulnerability scanners do provide severity ratings and impact classifications, making this a lesser concern.
  • Option C is incorrect because while point-in-time scanning is a real limitation, it doesn't directly threaten the accuracy of results the way software flaws do across all four described scenarios.

Memory Tip: Think of it this way - "Who watches the watchman?" If the security tool itself is flawed, no scenario is safe, making tool reliability the most fundamental concern. Remember: D = Defective tool = Danger to everything.

Topics

#Vulnerability Scanning#Vulnerability Assessment#Tool Limitations#Software Reliability

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice