Courseiva
Vulnerability Management →hardMultiple Choice

CS0-003 Vulnerability Management Practice Question

A cybersecurity analyst is configuring a vulnerability scanning policy for a mixed environment of Linux servers and Windows workstations. The analyst wants to minimize disruption to production services while ensuring comprehensive coverage. Which approach is BEST?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use separate scan windows for Linux servers and Windows workstations with appropriate credentials and performance tuning

Using separate scan windows and credentials for each OS type minimizes disruption by scanning similar systems together and reduces load, while tailored credential profiles improve scan accuracy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy agents on all systems to perform continuous scanning

    Why it's wrong here

    While agent-based scanning provides deep visibility, deploying agents on every single system introduces significant administrative overhead and performance degradation on resource-constrained hosts. Furthermore, legacy systems, network appliances, and IoT devices often do not support agent installation, making a universal agent deployment strategy technically unfeasible.

  • ✗

    Scan all systems simultaneously with minimal plugin set to avoid performance issues

    Why it's wrong here

    Restricting the vulnerability scanner to a minimal plugin set severely limits the depth of the assessment, leaving critical security flaws undetected. Additionally, initiating simultaneous scans across all systems can saturate network bandwidth and overwhelm hypervisors, even with a reduced plugin footprint.

  • ✓

    Use separate scan windows for Linux servers and Windows workstations with appropriate credentials and performance tuning

    Why this is correct

    Segmenting scans by operating system allows the analyst to apply targeted credentials, which enables deep, authenticated configuration audits without generating excessive network noise. Implementing distinct scan windows and performance tuning prevents resource exhaustion on production servers and ensures that workstation scans do not disrupt business operations.

  • ✗

    Schedule a single scan of all systems using default credentials and aggressive plugin settings

    Why it's wrong here

    Utilizing aggressive plugin settings in a single, massive scan job risks triggering denial-of-service conditions on sensitive network services and legacy hosts. Moreover, relying on default credentials will fail to authenticate against hardened systems, resulting in incomplete, unprivileged scans that miss critical local vulnerabilities.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.