CAS-003 · Question #338
A security engineer is performing an assessment again for a company. The security engineer examines the following output from the review: Which of the following tools is the engineer utilizing to…
The correct answer is B. SCAP scanner. SCAP (Security Content Automation Protocol) is a NIST-defined framework that uses standardized languages (OVAL, XCCDF, CVE, CVSS) to automate vulnerability management and policy compliance evaluation. A SCAP scanner audits system configurations against defined security…
Question
A security engineer is performing an assessment again for a company. The security engineer examines the following output from the review:
Which of the following tools is the engineer utilizing to perform this assessment?
Options
- AVulnerability scanner
- BSCAP scanner
- CPort scanner
- DInterception proxy
How the community answered
(28 responses)- A4% (1)
- B86% (24)
- C7% (2)
- D4% (1)
Explanation
SCAP (Security Content Automation Protocol) is a NIST-defined framework that uses standardized languages (OVAL, XCCDF, CVE, CVSS) to automate vulnerability management and policy compliance evaluation. A SCAP scanner audits system configurations against defined security baselines (such as DISA STIGs or CIS Benchmarks) and produces structured compliance reports. This type of output - showing system settings measured against a known security standard - is the hallmark of a SCAP scanner, distinguishing it from a vulnerability scanner (which finds exploitable flaws), a port scanner (which maps open ports), or an interception proxy (which intercepts HTTP traffic).
Topics
Community Discussion
No community discussion yet for this question.