nerdexam
(ISC)2

SSCP · Question #163

A network-based vulnerability assessment is a type of test also referred to as:

The correct answer is A. An active vulnerability assessment. A network-based vulnerability assessment probes target systems across the network by sending specially crafted packets and analyzing responses - mimicking what an external attacker would do. Because it actively sends traffic to elicit responses, it is classified as an active…

Submitted by saadiq_pk· Apr 18, 2026Network and Communications Security

Question

A network-based vulnerability assessment is a type of test also referred to as:

Options

  • AAn active vulnerability assessment.
  • BA routing vulnerability assessment.
  • CA host-based vulnerability assessment.
  • DA passive vulnerability assessment.

How the community answered

(30 responses)
  • A
    90% (27)
  • B
    3% (1)
  • C
    7% (2)

Explanation

A network-based vulnerability assessment probes target systems across the network by sending specially crafted packets and analyzing responses - mimicking what an external attacker would do. Because it actively sends traffic to elicit responses, it is classified as an active vulnerability assessment. This contrasts with a passive vulnerability assessment, which only monitors and analyzes traffic that already exists on the network (e.g., sniffing) without generating new probe traffic. A host-based assessment runs directly on the target machine using local agents or credentials, not over the network.

Topics

#Vulnerability Assessment#Network Scanning#Active Scanning

Community Discussion

No community discussion yet for this question.

Full SSCP Practice