CAS-003 · Question #933
An ICS security engineer is performing a security assessment at a bank in Chicago. The engineer reviews the following output: Which of the following tools is the engineer using the provide this…
The correct answer is A. SCAP scanner. SCAP (Security Content Automation Protocol) is a NIST-defined framework that standardizes the format and language for communicating security-related information. A SCAP scanner produces structured, standardized output showing compliance posture against benchmarks (such as STIG…
Question
An ICS security engineer is performing a security assessment at a bank in Chicago. The engineer reviews the following output:
Which of the following tools is the engineer using the provide this output?
Options
- ASCAP scanner
- BShodan
- CFuzzer
- DVulnerability scanner
How the community answered
(29 responses)- A86% (25)
- B3% (1)
- C7% (2)
- D3% (1)
Explanation
SCAP (Security Content Automation Protocol) is a NIST-defined framework that standardizes the format and language for communicating security-related information. A SCAP scanner produces structured, standardized output showing compliance posture against benchmarks (such as STIG or CIS Controls) using components like XCCDF, OVAL, and CVE identifiers. For an Industrial Control System (ICS) security assessment at a financial institution, a SCAP scanner is the appropriate tool because it can evaluate configurations against regulatory and security baselines in a formal, auditable format. Shodan (B) is a search engine for internet-exposed devices. A fuzzer (C) sends malformed inputs to find software bugs. A generic vulnerability scanner (D) identifies weaknesses but does not use the SCAP standardized protocol and output format.
Topics
Community Discussion
No community discussion yet for this question.