nerdexam
CompTIA

SY0-501 · Question #298

During a recent audit, it was discovered that many services and desktops were missing security patches. Which of the following BEST describes the assessment that was performed to discover this issue?

The correct answer is B. Vulnerability scan. During a recent audit, the discovery of missing security patches on services and desktops is best identified through a vulnerability scan, which actively assesses systems for known weaknesses.

Submitted by ngozi_ng· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

During a recent audit, it was discovered that many services and desktops were missing security patches. Which of the following BEST describes the assessment that was performed to discover this issue?

Options

  • ANetwork mapping
  • BVulnerability scan
  • CPort Scan
  • DProtocol analysis

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    75% (27)
  • C
    14% (5)
  • D
    8% (3)

Why each option

During a recent audit, the discovery of missing security patches on services and desktops is best identified through a vulnerability scan, which actively assesses systems for known weaknesses.

ANetwork mapping

Network mapping is used to discover devices, their connections, and the topology of a network, not to assess their patch status or vulnerabilities.

BVulnerability scanCorrect

A vulnerability scan is specifically designed to identify security weaknesses, misconfigurations, and missing security updates or patches on systems, services, and applications. These scans compare the target system's current state against a database of known vulnerabilities and patch requirements, directly addressing the discovery of 'missing security patches'.

CPort Scan

A port scan identifies which ports are open on a host, indicating active services, but does not determine if those services have missing security patches.

DProtocol analysis

Protocol analysis involves capturing and interpreting network traffic to understand communication patterns, troubleshoot issues, or detect anomalies, not to find missing security patches on endpoints.

Concept tested: Identifying security weaknesses with vulnerability scanning

Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/vulnerability-assessment-recommendations-azure-machines

Topics

#vulnerability scanning#patch management#security assessment#missing patches

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice