nerdexam
CompTIA

CAS-003 · Question #338

A security engineer is performing an assessment again for a company. The security engineer examines the following output from the review: Which of the following tools is the engineer utilizing to…

The correct answer is B. SCAP scanner. SCAP (Security Content Automation Protocol) is a NIST-defined framework that uses standardized languages (OVAL, XCCDF, CVE, CVSS) to automate vulnerability management and policy compliance evaluation. A SCAP scanner audits system configurations against defined security…

Enterprise Security Operations

Question

A security engineer is performing an assessment again for a company. The security engineer examines the following output from the review:

Which of the following tools is the engineer utilizing to perform this assessment?

Options

  • AVulnerability scanner
  • BSCAP scanner
  • CPort scanner
  • DInterception proxy

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    86% (24)
  • C
    7% (2)
  • D
    4% (1)

Explanation

SCAP (Security Content Automation Protocol) is a NIST-defined framework that uses standardized languages (OVAL, XCCDF, CVE, CVSS) to automate vulnerability management and policy compliance evaluation. A SCAP scanner audits system configurations against defined security baselines (such as DISA STIGs or CIS Benchmarks) and produces structured compliance reports. This type of output - showing system settings measured against a known security standard - is the hallmark of a SCAP scanner, distinguishing it from a vulnerability scanner (which finds exploitable flaws), a port scanner (which maps open ports), or an interception proxy (which intercepts HTTP traffic).

Topics

#SCAP#compliance scanning#security assessment tools#configuration auditing

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice