nerdexam
CompTIA

CS0-003 · Question #383

An analyst needs to provide recommendations based on a recent vulnerability scan: Which of the following should the analyst recommend addressing to ensure potential vulnerabilities are identified?

The correct answer is D. Scan not performed with admin privileges. Explanation Running a scan without admin privileges (option D) is the correct recommendation because unprivileged scans cannot access certain system areas, services, or configurations, meaning many vulnerabilities will go undetected - the scan produces an incomplete picture of th

Submitted by thandi_sa· Mar 6, 2026Vulnerability Management

Question

An analyst needs to provide recommendations based on a recent vulnerability scan:

Which of the following should the analyst recommend addressing to ensure potential vulnerabilities are identified?

Exhibit

CS0-003 question #383 exhibit

Options

  • ASMB use domain SID to enumerate users
  • BSYN scanner
  • CSSL certificate cannot be trusted
  • DScan not performed with admin privileges

How the community answered

(27 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    93% (25)

Explanation

Explanation

Running a scan without admin privileges (option D) is the correct recommendation because unprivileged scans cannot access certain system areas, services, or configurations, meaning many vulnerabilities will go undetected - the scan produces an incomplete picture of the attack surface. This is a fundamental scan configuration issue that must be addressed to ensure potential vulnerabilities are properly identified.

Why the distractors are wrong:

  • A (SMB SID enumeration): This is an actual finding/vulnerability discovered by the scan, not a scanning configuration problem
  • B (SYN scanner): This refers to the scan type/method being used, not a gap in vulnerability identification coverage
  • C (SSL certificate cannot be trusted): Like option A, this is a specific vulnerability result from the scan, not a configuration issue affecting scan completeness

Memory Tip: Think of the question's key phrase - "potential vulnerabilities are identified." Ask yourself: "What would cause me to MISS vulnerabilities?" A scan lacking admin/root privileges can't see everything "under the hood," so it's the only option describing a scanning limitation rather than a scan result. When you see "ensure vulnerabilities are identified," look for the answer about scan configuration, not scan findings.

Topics

#Vulnerability Scanning#Scan Configuration#Privilege Escalation (Scanning)#Vulnerability Identification

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice