PT0-001 · Question #86
The results of a basic compliance scan show a subset of assets on a network. This data differs from what is shown on the network architecture diagram, which was supplied at the beginning of the…
The correct answer is A. Storage access B. Limited network access. When a compliance scan returns fewer assets than the network diagram shows, the scanner likely lacked visibility into storage network segments or was constrained to a limited portion of the network.
Question
The results of a basic compliance scan show a subset of assets on a network. This data differs from what is shown on the network architecture diagram, which was supplied at the beginning of the test. Which of the following are the MOST likely causes for this difference? (Select TWO)
Options
- AStorage access
- BLimited network access
- CMisconfigured DHCP server
- DIncorrect credentials
- ENetwork access controls
How the community answered
(30 responses)- A80% (24)
- C3% (1)
- D10% (3)
- E7% (2)
Why each option
When a compliance scan returns fewer assets than the network diagram shows, the scanner likely lacked visibility into storage network segments or was constrained to a limited portion of the network.
Storage systems such as SANs or NAS devices often reside on dedicated storage VLANs or fabric networks isolated from the general IP network, making them invisible to a basic compliance scanner that only has access to the primary network segment.
If the scanner is provisioned with limited network access - such as a single DHCP address on one VLAN - it cannot discover or scan assets residing on other subnets or network segments, producing an incomplete asset inventory compared to the full architecture diagram.
A misconfigured DHCP server would affect IP address assignment for endpoints but would not reduce the number of devices visible to a network scanner that has already obtained connectivity.
Incorrect credentials would cause authentication or enumeration failures on discovered hosts but would not prevent the scanner from detecting that those hosts exist on the network.
Network access controls could restrict scanner traffic in ways that overlap with limited network access, but as a distinct answer choice it is less precisely the root cause compared to B, which directly describes the scanner's constrained network reach.
Concept tested: Compliance scan scope limitations and network segment visibility
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.