nerdexam
CompTIA

SY0-501 · Question #410

Which of the following should a security analyst perform FIRST to determine the vulnerabilities of a legacy system?

The correct answer is A. Passive scan. To determine vulnerabilities in a legacy system, a security analyst should first perform a passive scan to gather information non-intrusively and minimize the risk of disrupting potentially fragile systems.

Submitted by tyler.j· Mar 4, 2026Security operations

Question

Which of the following should a security analyst perform FIRST to determine the vulnerabilities of a legacy system?

Options

  • APassive scan
  • BAggressive scan
  • CCredentialed scan
  • DIntrusive scan

How the community answered

(36 responses)
  • A
    78% (28)
  • B
    14% (5)
  • C
    6% (2)
  • D
    3% (1)

Why each option

To determine vulnerabilities in a legacy system, a security analyst should first perform a passive scan to gather information non-intrusively and minimize the risk of disrupting potentially fragile systems.

APassive scanCorrect

A passive scan gathers information without directly interacting with or risking the stability of a potentially fragile legacy system. This non-intrusive method is crucial as a first step to identify basic vulnerabilities and gather intelligence without causing service interruptions or system failures on critical, sensitive, or unstable infrastructure.

BAggressive scan

Aggressive scans actively probe the system and could disrupt fragile legacy systems, making them unsuitable as a first step.

CCredentialed scan

Credentialed scans require direct access and elevated privileges, making them more intrusive than a passive scan and typically not the first step for initial discovery on a potentially unknown legacy system.

DIntrusive scan

Intrusive scans directly interact with the system and carry a higher risk of disruption, making them inappropriate as a first step for a legacy system.

Concept tested: Vulnerability scanning methodology for legacy systems

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf

Topics

#vulnerability scanning#passive scan#legacy systems#assessment methodology

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice