nerdexam
CompTIA

SY0-501 · Question #470

A security analyst is reviewing an assessment report that includes software versions, running services, supported encryption algorithms, and permission settings. Which of the following produced the…

The correct answer is A. Vulnerability scanner. The described report, containing software versions, running services, encryption algorithms, and permission settings, is a typical output generated by a vulnerability scanner.

Submitted by viktor_hu· Mar 4, 2026Security operations

Question

A security analyst is reviewing an assessment report that includes software versions, running services, supported encryption algorithms, and permission settings. Which of the following produced the report?

Options

  • AVulnerability scanner
  • BProtocol analyzer
  • CNetwork mapper
  • DWeb inspector

How the community answered

(49 responses)
  • A
    80% (39)
  • B
    2% (1)
  • C
    12% (6)
  • D
    6% (3)

Why each option

The described report, containing software versions, running services, encryption algorithms, and permission settings, is a typical output generated by a vulnerability scanner.

AVulnerability scannerCorrect

A vulnerability scanner is specifically designed to identify security weaknesses by examining systems for outdated software versions, misconfigured services, weak encryption algorithms, and improper permission settings. The comprehensive report detailing these specific technical aspects directly aligns with the capabilities and typical output of such a tool, which aims to pinpoint potential security flaws.

BProtocol analyzer

Protocol analyzers capture and dissect network traffic, focusing on communication flows and packet content, not on system configurations or software versions.

CNetwork mapper

Network mappers discover devices on a network and their connectivity, often identifying open ports, but they do not typically delve into detailed software versions, encryption algorithms, or permission settings.

DWeb inspector

Web inspectors are browser-based development tools used for debugging web applications, examining client-side HTML, CSS, and JavaScript, not for comprehensive system security assessments.

Concept tested: Security tool functions (Vulnerability Scanner)

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-vulnerability-management/tvm-overview?view=o365-worldwide

Topics

#vulnerability scanning#security assessment tools#enumeration

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice