PT0-003 · Question #19
During a vulnerability assessment, a penetration tester configures the scanner sensor and performs the initial vulnerability scanning under the client's internal network. The tester later discusses th
The correct answer is B. Performed a discovery scan.. When the client indicates that the scope's hosts and assets are not included in the vulnerability scan results, it suggests that the tester may have missed discovering all the devices in the scope. Performing a Discovery Scan: Purpose: A discovery scan identifies all active devic
Question
During a vulnerability assessment, a penetration tester configures the scanner sensor and performs the initial vulnerability scanning under the client's internal network. The tester later discusses the results with the client, but the client does not accept the results. The client indicates the host and assets that were within scope are not included in the vulnerability scan results. Which of the following should the tester have done?
Options
- ARechecked the scanner configuration.
- BPerformed a discovery scan.
- CUsed a different scan engine.
- DConfigured all the TCP ports on the scan.
How the community answered
(51 responses)- A8% (4)
- B78% (40)
- C4% (2)
- D10% (5)
Explanation
When the client indicates that the scope's hosts and assets are not included in the vulnerability scan results, it suggests that the tester may have missed discovering all the devices in the scope. Performing a Discovery Scan: Purpose: A discovery scan identifies all active devices on the network before running a detailed vulnerability scan. It ensures that all in-scope devices are included in the assessment. Process: The discovery scan uses techniques like ping sweeps, ARP scans, and port scans to identify active hosts and services.
Topics
Community Discussion
No community discussion yet for this question.