SY0-301 · Question #289
An administrator is concerned that a company's web server has not been patched. Which of the following would be the BEST assessment for the administrator to perform?
The correct answer is A. Vulnerability scan. A vulnerability scan proactively identifies known security weaknesses in systems, including missing patches, outdated software versions, and unaddressed CVEs (Common Vulnerabilities and Exposures). It is the most direct tool to assess whether a web server is missing critical…
Question
An administrator is concerned that a company's web server has not been patched. Which of the following would be the BEST assessment for the administrator to perform?
Options
- AVulnerability scan
- BRisk assessment
- CVirus scan
- DNetwork sniffer
How the community answered
(31 responses)- A94% (29)
- B3% (1)
- C3% (1)
Explanation
A vulnerability scan proactively identifies known security weaknesses in systems, including missing patches, outdated software versions, and unaddressed CVEs (Common Vulnerabilities and Exposures). It is the most direct tool to assess whether a web server is missing critical patches. A risk assessment (B) is a broader business-level process that evaluates the overall risk posture and is not focused on detecting specific missing patches. A virus scan (C) detects malware but does not identify unpatched software. A network sniffer (D) captures and analyzes network traffic but provides no information about patch status on a server.
Topics
Community Discussion
No community discussion yet for this question.