CS0-003 Vulnerability Management Practice Question
A cybersecurity analyst is configuring a vulnerability scanning policy for a mixed environment of Linux servers and Windows workstations. The analyst wants to minimize disruption to production services while ensuring comprehensive coverage. Which approach is BEST?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use separate scan windows for Linux servers and Windows workstations with appropriate credentials and performance tuning
Using separate scan windows and credentials for each OS type minimizes disruption by scanning similar systems together and reduces load, while tailored credential profiles improve scan accuracy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy agents on all systems to perform continuous scanning
Why it's wrong here
While agent-based scanning provides deep visibility, deploying agents on every single system introduces significant administrative overhead and performance degradation on resource-constrained hosts. Furthermore, legacy systems, network appliances, and IoT devices often do not support agent installation, making a universal agent deployment strategy technically unfeasible.
- ✗
Scan all systems simultaneously with minimal plugin set to avoid performance issues
Why it's wrong here
Restricting the vulnerability scanner to a minimal plugin set severely limits the depth of the assessment, leaving critical security flaws undetected. Additionally, initiating simultaneous scans across all systems can saturate network bandwidth and overwhelm hypervisors, even with a reduced plugin footprint.
- ✓
Use separate scan windows for Linux servers and Windows workstations with appropriate credentials and performance tuning
Why this is correct
Segmenting scans by operating system allows the analyst to apply targeted credentials, which enables deep, authenticated configuration audits without generating excessive network noise. Implementing distinct scan windows and performance tuning prevents resource exhaustion on production servers and ensures that workstation scans do not disrupt business operations.
- ✗
Schedule a single scan of all systems using default credentials and aggressive plugin settings
Why it's wrong here
Utilizing aggressive plugin settings in a single, massive scan job risks triggering denial-of-service conditions on sensitive network services and legacy hosts. Moreover, relying on default credentials will fail to authenticate against hardened systems, resulting in incomplete, unprivileged scans that miss critical local vulnerabilities.
Go deeper
Related to this question
Learn chapter
Nessus Vulnerability Scanner
Key term
Vulnerability scanning
Vulnerability scanning is an automated process that identifies security weaknesses in systems, networks, and applications by comparing them against known vulnerability databases.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.