SY0-501 · Question #437
A security analyst conducts a manual scan on a known hardened host that identifies many non- compliant items. Which of the following BEST describe why this has occurred? (Select TWO)
The correct answer is B. Non-applicable plug ins were selected in the scan policy C. The incorrect audit file was used. When a vulnerability scan on a hardened host unexpectedly reports many non-compliant items, the most likely causes are misconfigured scan policies or incorrect audit/benchmark files being applied during the assessment.
Question
A security analyst conducts a manual scan on a known hardened host that identifies many non- compliant items. Which of the following BEST describe why this has occurred? (Select TWO)
Options
- APrivileged-user certificated were used to scan the host
- BNon-applicable plug ins were selected in the scan policy
- CThe incorrect audit file was used
- DThe output of the report contains false positives
- EThe target host has been compromised
How the community answered
(28 responses)- A14% (4)
- B75% (21)
- D4% (1)
- E7% (2)
Why each option
When a vulnerability scan on a hardened host unexpectedly reports many non-compliant items, the most likely causes are misconfigured scan policies or incorrect audit/benchmark files being applied during the assessment.
Using privileged credentials actually improves scan accuracy by allowing deeper access to the host, and would more likely reduce false positives rather than generate excessive non-compliant findings.
Selecting non-applicable plugins in the scan policy causes the scanner to check for vulnerabilities or configurations that do not apply to the target OS or application, generating false non-compliance findings that misrepresent the host's actual security posture.
Audit files define the specific compliance benchmarks (e.g., CIS, STIG) checked against the host; using an incorrect audit file - such as applying a Windows benchmark to a Linux host - will produce numerous spurious non-compliant results because the checks do not match the target system's configuration.
While false positives can occur in scan results, this choice describes a symptom rather than a root cause explaining why a hardened host shows many non-compliant items.
A compromised host is possible but is not the best explanation for many non-compliant findings on a known hardened host, as the scenario points to a scanning configuration issue rather than an active breach.
Concept tested: Vulnerability scan policy and audit file misconfiguration
Source: https://docs.tenable.com/nessus/Content/ScanAndPolicyTemplates.htm
Topics
Community Discussion
No community discussion yet for this question.