nerdexam
CompTIA

CS0-003 · Question #185

A company is in the process of implementing a vulnerability management program. Which of the following scanning methods should be implemented to minimize the risk of OT/ICS devices malfunctioning…

The correct answer is B. Passive scanning. Passive scanning is a method of vulnerability identification that does not send any packets or probes to the target devices, but rather observes and analyzes the network traffic passively. Passive scanning can minimize the risk of OT/ICS devices malfunctioning due to the…

Submitted by eva_at· Mar 6, 2026Vulnerability Management

Question

A company is in the process of implementing a vulnerability management program. Which of the following scanning methods should be implemented to minimize the risk of OT/ICS devices malfunctioning due to the vulnerability identification process?

Options

  • ANon-credentialed scanning
  • BPassive scanning
  • CAgent-based scanning
  • DCredentialed scanning

How the community answered

(65 responses)
  • A
    5% (3)
  • B
    85% (55)
  • C
    9% (6)
  • D
    2% (1)

Explanation

Passive scanning is a method of vulnerability identification that does not send any packets or probes to the target devices, but rather observes and analyzes the network traffic passively. Passive scanning can minimize the risk of OT/ICS devices malfunctioning due to the vulnerability identification process, as it does not interfere with the normal operation of the devices or cause any network disruption. Passive scanning can also detect vulnerabilities that active scanning may miss, such as misconfigured devices, rogue devices or unauthorized traffic.

Topics

#Vulnerability scanning#OT/ICS security#Passive scanning#Risk minimization

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice