nerdexam
CompTIA

CAS-003 · Question #933

An ICS security engineer is performing a security assessment at a bank in Chicago. The engineer reviews the following output: Which of the following tools is the engineer using the provide this…

The correct answer is A. SCAP scanner. SCAP (Security Content Automation Protocol) is a NIST-defined framework that standardizes the format and language for communicating security-related information. A SCAP scanner produces structured, standardized output showing compliance posture against benchmarks (such as STIG…

Enterprise Security Operations

Question

An ICS security engineer is performing a security assessment at a bank in Chicago. The engineer reviews the following output:

Which of the following tools is the engineer using the provide this output?

Options

  • ASCAP scanner
  • BShodan
  • CFuzzer
  • DVulnerability scanner

How the community answered

(29 responses)
  • A
    86% (25)
  • B
    3% (1)
  • C
    7% (2)
  • D
    3% (1)

Explanation

SCAP (Security Content Automation Protocol) is a NIST-defined framework that standardizes the format and language for communicating security-related information. A SCAP scanner produces structured, standardized output showing compliance posture against benchmarks (such as STIG or CIS Controls) using components like XCCDF, OVAL, and CVE identifiers. For an Industrial Control System (ICS) security assessment at a financial institution, a SCAP scanner is the appropriate tool because it can evaluate configurations against regulatory and security baselines in a formal, auditable format. Shodan (B) is a search engine for internet-exposed devices. A fuzzer (C) sends malformed inputs to find software bugs. A generic vulnerability scanner (D) identifies weaknesses but does not use the SCAP standardized protocol and output format.

Topics

#SCAP#ICS security#security assessment tools#vulnerability scanning

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice