nerdexam
CompTIA

SY0-301 · Question #768

Which of the following allows a technician to scan for missing patches on a device without actually attempting to exploit the security problem?

The correct answer is A. A vulnerability scanner. A vulnerability scanner performs non-intrusive assessments of systems by comparing installed software versions, patch levels, and configurations against a database of known vulnerabilities. It identifies missing patches and misconfigurations without attempting to exploit them…

Threats, vulnerabilities, and mitigations

Question

Which of the following allows a technician to scan for missing patches on a device without actually attempting to exploit the security problem?

Options

  • AA vulnerability scanner
  • BSecurity baselines
  • CA port scanner
  • DGroup policy

How the community answered

(32 responses)
  • A
    94% (30)
  • C
    3% (1)
  • D
    3% (1)

Explanation

A vulnerability scanner performs non-intrusive assessments of systems by comparing installed software versions, patch levels, and configurations against a database of known vulnerabilities. It identifies missing patches and misconfigurations without attempting to exploit them - this is known as a credentialed or non-exploiting scan. This distinguishes it from a penetration test or exploit framework. Security baselines define desired secure configurations but are not scanning tools. A port scanner only identifies open ports and running services, not patch status. Group Policy enforces configurations but does not scan for vulnerabilities.

Topics

#vulnerability scanner#patch management#non-intrusive scanning#security assessment

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice