nerdexam
CompTIA

SY0-501 · Question #365

Which of the following is commonly done as part of a vulnerability scan?

The correct answer is D. Identifying unpatched workstations. A vulnerability scan systematically identifies potential security weaknesses and misconfigurations in systems without actively exploiting them.

Submitted by dimitri_ru· Mar 4, 2026Security operations

Question

Which of the following is commonly done as part of a vulnerability scan?

Options

  • AExploiting misconfigured applications
  • BCracking employee passwords
  • CSending phishing emails to employees
  • DIdentifying unpatched workstations

How the community answered

(29 responses)
  • A
    14% (4)
  • B
    10% (3)
  • C
    3% (1)
  • D
    72% (21)

Why each option

A vulnerability scan systematically identifies potential security weaknesses and misconfigurations in systems without actively exploiting them.

AExploiting misconfigured applications

Exploiting misconfigured applications is characteristic of penetration testing, which actively attempts to breach systems, rather than a non-intrusive vulnerability scan.

BCracking employee passwords

Cracking employee passwords is typically part of a password audit or a penetration test, not a standard function of a vulnerability scan.

CSending phishing emails to employees

Sending phishing emails is a social engineering technique used in penetration testing or security awareness training, which is distinct from a technical vulnerability scan.

DIdentifying unpatched workstationsCorrect

Vulnerability scans are designed to identify known security flaws, such as missing security updates, unpatched software, or misconfigurations on workstations and servers. These scans compare system information against databases of known vulnerabilities to flag systems that are susceptible to attack due to a lack of proper patching.

Concept tested: Vulnerability Scanning Purpose and Activities

Source: https://csrc.nist.gov/glossary/term/vulnerability-scan

Topics

#vulnerability scanning#patch management#unpatched systems#security assessment

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice