SY0-501 · Question #365
Which of the following is commonly done as part of a vulnerability scan?
The correct answer is D. Identifying unpatched workstations. A vulnerability scan systematically identifies potential security weaknesses and misconfigurations in systems without actively exploiting them.
Question
Which of the following is commonly done as part of a vulnerability scan?
Options
- AExploiting misconfigured applications
- BCracking employee passwords
- CSending phishing emails to employees
- DIdentifying unpatched workstations
How the community answered
(29 responses)- A14% (4)
- B10% (3)
- C3% (1)
- D72% (21)
Why each option
A vulnerability scan systematically identifies potential security weaknesses and misconfigurations in systems without actively exploiting them.
Exploiting misconfigured applications is characteristic of penetration testing, which actively attempts to breach systems, rather than a non-intrusive vulnerability scan.
Cracking employee passwords is typically part of a password audit or a penetration test, not a standard function of a vulnerability scan.
Sending phishing emails is a social engineering technique used in penetration testing or security awareness training, which is distinct from a technical vulnerability scan.
Vulnerability scans are designed to identify known security flaws, such as missing security updates, unpatched software, or misconfigurations on workstations and servers. These scans compare system information against databases of known vulnerabilities to flag systems that are susceptible to attack due to a lack of proper patching.
Concept tested: Vulnerability Scanning Purpose and Activities
Source: https://csrc.nist.gov/glossary/term/vulnerability-scan
Topics
Community Discussion
No community discussion yet for this question.