nerdexam
CompTIA

PT0-001 · Question #86

The results of a basic compliance scan show a subset of assets on a network. This data differs from what is shown on the network architecture diagram, which was supplied at the beginning of the…

The correct answer is A. Storage access B. Limited network access. When a compliance scan returns fewer assets than the network diagram shows, the scanner likely lacked visibility into storage network segments or was constrained to a limited portion of the network.

Reconnaissance and enumeration

Question

The results of a basic compliance scan show a subset of assets on a network. This data differs from what is shown on the network architecture diagram, which was supplied at the beginning of the test. Which of the following are the MOST likely causes for this difference? (Select TWO)

Options

  • AStorage access
  • BLimited network access
  • CMisconfigured DHCP server
  • DIncorrect credentials
  • ENetwork access controls

How the community answered

(30 responses)
  • A
    80% (24)
  • C
    3% (1)
  • D
    10% (3)
  • E
    7% (2)

Why each option

When a compliance scan returns fewer assets than the network diagram shows, the scanner likely lacked visibility into storage network segments or was constrained to a limited portion of the network.

AStorage accessCorrect

Storage systems such as SANs or NAS devices often reside on dedicated storage VLANs or fabric networks isolated from the general IP network, making them invisible to a basic compliance scanner that only has access to the primary network segment.

BLimited network accessCorrect

If the scanner is provisioned with limited network access - such as a single DHCP address on one VLAN - it cannot discover or scan assets residing on other subnets or network segments, producing an incomplete asset inventory compared to the full architecture diagram.

CMisconfigured DHCP server

A misconfigured DHCP server would affect IP address assignment for endpoints but would not reduce the number of devices visible to a network scanner that has already obtained connectivity.

DIncorrect credentials

Incorrect credentials would cause authentication or enumeration failures on discovered hosts but would not prevent the scanner from detecting that those hosts exist on the network.

ENetwork access controls

Network access controls could restrict scanner traffic in ways that overlap with limited network access, but as a distinct answer choice it is less precisely the root cause compared to B, which directly describes the scanner's constrained network reach.

Concept tested: Compliance scan scope limitations and network segment visibility

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#network discovery#compliance scanning#asset inventory#scan discrepancy

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice