nerdexam
EC-Council

312-50V13 · Question #64

Your company was hired by a small healthcare provider to perform a technical assessment on the network. What is the best approach for discovering vulnerabilities on a Windows-based computer?

The correct answer is B. Use a scan tool like Nessus. To discover vulnerabilities on a Windows-based computer, a dedicated vulnerability scanning tool is the most effective approach as it automates the process of identifying known security weaknesses. Nessus is a widely recognized and comprehensive vulnerability scanner capable of…

Submitted by anna_se· Mar 6, 2026Vulnerability Analysis

Question

Your company was hired by a small healthcare provider to perform a technical assessment on the network. What is the best approach for discovering vulnerabilities on a Windows-based computer?

Options

  • AUse the built-in Windows Update tool
  • BUse a scan tool like Nessus
  • CCheck MITRE.org for the latest list of CVE findings
  • DCreate a disk image of a clean Windows installation

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    89% (17)
  • D
    5% (1)

Why each option

To discover vulnerabilities on a Windows-based computer, a dedicated vulnerability scanning tool is the most effective approach as it automates the process of identifying known security weaknesses. Nessus is a widely recognized and comprehensive vulnerability scanner capable of assessing operating systems and applications for security flaws.

AUse the built-in Windows Update tool

The built-in Windows Update tool is designed to apply security patches and updates to the operating system and installed Microsoft software, not to actively scan for and report on existing vulnerabilities.

BUse a scan tool like NessusCorrect

Nessus is a commercial vulnerability scanner that is widely used to identify security misconfigurations, missing patches, default credentials, and other vulnerabilities on various operating systems, including Windows. It actively probes the target system to provide a detailed report of potential weaknesses.

CCheck MITRE.org for the latest list of CVE findings

MITRE.org provides a public repository of Common Vulnerabilities and Exposures (CVEs), which is a database of known security flaws, but it is not a tool that can be used to scan a system for these vulnerabilities.

DCreate a disk image of a clean Windows installation

Creating a disk image of a clean Windows installation is a method for system deployment, backup, or forensic analysis, and it does not actively scan a live system for vulnerabilities.

Concept tested: Vulnerability scanning tools

Source: https://www.cisco.com/c/en/us/products/security/network-vulnerability-assessment.html

Topics

#vulnerability scanning#Nessus#vulnerability assessment tools#Windows security

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice