CAS-003 · Question #735
A system administrator recently conducted a vulnerability scan of the internet. Subsequently, the organization was successfully attacked by an adversary. Which of the following in the MOST likely…
The correct answer is B. The system administrator did not perform a full system sun. The administrator scanned 'the internet' (likely only external-facing assets) rather than conducting a comprehensive scan of all internal systems. This incomplete scope left internal vulnerable hosts undiscovered and unpatched, giving attackers an undetected entry point. Option…
Question
A system administrator recently conducted a vulnerability scan of the internet. Subsequently, the organization was successfully attacked by an adversary. Which of the following in the MOST likely explanation for why the organization network was compromised?
Options
- AThere was a false positive since the network was fully patched.
- BThe system administrator did not perform a full system sun.
- CThe systems administrator performed a credentialed scan.
- DThe vulnerability database was not updated.
How the community answered
(24 responses)- A4% (1)
- B75% (18)
- C8% (2)
- D13% (3)
Explanation
The administrator scanned 'the internet' (likely only external-facing assets) rather than conducting a comprehensive scan of all internal systems. This incomplete scope left internal vulnerable hosts undiscovered and unpatched, giving attackers an undetected entry point. Option A is incorrect because false positives report non-existent vulnerabilities - they would not cause a missed compromise. Option C is incorrect because credentialed scans are actually more thorough than unauthenticated scans, not less. Option D (outdated vulnerability database) is plausible but is secondary to the more fundamental problem of not scanning all systems in the first place.
Topics
Community Discussion
No community discussion yet for this question.