nerdexam
CompTIA

N10-005 · Question #725

An administrator would like to scan for open ports on the subnet and determine if any vulnerable applications are listening. Which of the following tools would the administrator MOST likely use?

The correct answer is B. Nessus. Nessus is a dedicated vulnerability scanner that performs port scanning and identifies vulnerable services or applications listening on those ports across a subnet.

Network security

Question

An administrator would like to scan for open ports on the subnet and determine if any vulnerable applications are listening. Which of the following tools would the administrator MOST likely use?

Options

  • APing
  • BNessus
  • CIMAP
  • DTelnet

How the community answered

(20 responses)
  • B
    95% (19)
  • C
    5% (1)

Why each option

Nessus is a dedicated vulnerability scanner that performs port scanning and identifies vulnerable services or applications listening on those ports across a subnet.

APing

Ping uses ICMP echo requests to test basic host reachability; it cannot scan for open ports or identify vulnerable applications.

BNessusCorrect

Nessus is a comprehensive vulnerability assessment tool that actively probes hosts on a subnet to discover open ports, identify the services running on them, and match those services against a database of known vulnerabilities. This makes it the appropriate tool for both port discovery and vulnerability identification in a single scan.

CIMAP

IMAP (Internet Message Access Protocol) is an email retrieval protocol used by mail clients to access mailboxes; it is not a network scanning or security assessment tool.

DTelnet

Telnet is an unencrypted remote terminal protocol that can manually connect to a single port on a single host to check if it is open, but it cannot scan a subnet or identify vulnerable applications automatically.

Concept tested: Vulnerability scanning with Nessus for open ports

Source: https://docs.tenable.com/nessus/Content/GetStarted.htm

Topics

#Nessus#vulnerability scanning#port scanning#security tools

Community Discussion

No community discussion yet for this question.

Full N10-005 Practice