312-50V9 · Question #52
Which of the following business challenges could be solved by using a vulnerability scanner?
The correct answer is D. There is a monthly requirement to test corporate compliance with host application usage and. Vulnerability scanners are best suited for scheduled, recurring compliance checks that verify whether host configurations and applications meet defined security standards.
Question
Which of the following business challenges could be solved by using a vulnerability scanner?
Options
- AAuditors want to discover if all systems are following a standard naming convention.
- BA web server was compromised and management needs to know if any further systems were
- CThere is an emergency need to remove administrator access from multiple machines for an
- DThere is a monthly requirement to test corporate compliance with host application usage and
How the community answered
(56 responses)- A4% (2)
- B7% (4)
- C13% (7)
- D77% (43)
Why each option
Vulnerability scanners are best suited for scheduled, recurring compliance checks that verify whether host configurations and applications meet defined security standards.
Auditing system naming conventions is a configuration management or asset inventory task that falls outside the scope of vulnerability scanner capabilities.
Determining whether additional systems were compromised after a breach is an incident response and forensic investigation function, not a vulnerability scanning use case.
Removing administrator access from multiple machines is an identity and access management operation that requires privileged account management tools, not a vulnerability scanner.
Vulnerability scanners are designed to run on a scheduled basis and compare host states against security policy baselines and compliance benchmarks, making them ideal for recurring monthly compliance testing of corporate host application usage and configurations. This use case maps directly to the scanner's ability to produce consistent, repeatable, and auditable reports against defined standards. Automated policy compliance scanning is one of the primary documented business justifications for deploying vulnerability scanners.
Concept tested: Vulnerability scanner business use cases and compliance auditing
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
Topics
Community Discussion
No community discussion yet for this question.