Courseiva
mediumMultiple Choice

Why Authenticated Scans Are Needed for Windows Patch Data

A scan of Windows servers reports few findings, but the scanner used no credentials. The security manager suspects missing patch data. What should be changed? For control selection, Which control best addresses the stated weakness without hiding risk?

⚠ Common exam trap

The CS0-004 exam often tests the misconception that increasing scan depth (e.g., port range or intensity) compensates for lack of authentication, but the trap here is that patch data is only accessible through authenticated access, not by broader network scanning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run authenticated scans using least-privilege scanner credentials

Unauthenticated scans only enumerate open ports and services visible without credentials, missing the patch status of installed software because they cannot query the Windows registry or WMI for installed updates. Running authenticated scans with least-privilege credentials allows the scanner to log into each target and retrieve detailed patch data via the Windows Update Agent API or registry keys, revealing missing patches that were previously invisible. This directly addresses the security manager's suspicion of missing patch data without introducing unnecessary risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run authenticated scans using least-privilege scanner credentials

    Why this is correct

    Authenticated scanning, utilizing least-privilege credentials, provides the vulnerability scanner with direct access to the target system's internal configuration, installed software inventory, and precise patch levels. This deep visibility allows for accurate identification of missing security updates, misconfigurations, and local vulnerabilities that unauthenticated scans cannot detect. Employing least privilege ensures that the scanner only has the necessary permissions to gather security-relevant data, minimizing potential attack surface if credentials are compromised.

  • ✗

    Increase only the port range

    Why it's wrong here

    Increasing only the port range for a vulnerability scan primarily expands the scope of network services probed, but it does not enable the scanner to inspect the internal state of the operating system or installed applications. While more open ports might reveal additional network-accessible services, this approach fails to provide critical information regarding patch levels, system configurations, or software versions that are not externally exposed. Therefore, it will not reliably improve the accuracy of findings related to internal system vulnerabilities.

  • ✗

    Disable host firewalls permanently

    Why it's wrong here

    Permanently disabling host firewalls is a severe security misconfiguration that significantly elevates the risk profile of Windows servers by exposing all services directly to the network. This action is entirely unnecessary for effective vulnerability scanning, as authenticated scans can operate through properly configured firewalls that permit specific, secure communication channels. Such a drastic measure creates an unacceptable attack surface, making systems vulnerable to a wide array of network-based exploits.

  • ✗

    Trust the unauthenticated result as complete

    Why it's wrong here

    Trusting unauthenticated scan results as complete for Windows servers is a critical oversight, as these scans are inherently limited to external observations and publicly exposed service banners. They lack the necessary access to query the operating system's registry, file system, or installed package managers to accurately determine patch status, internal configuration flaws, or application-specific vulnerabilities. Consequently, unauthenticated scans frequently report a low number of findings, creating a false sense of security by missing a significant portion of actual risks.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CS0-004

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A scan of Windows servers reports few findings, but the scanner used no credentials. The security manager suspects missing patch data. What should be changed? For tool configuration, Which scanner or pipeline change most directly improves result quality?

medium
  • A.Increase only the port range
  • B.Trust the unauthenticated result as complete
  • ✓ C.Run authenticated scans using least-privilege scanner credentials
  • D.Disable host firewalls permanently

Why C: Unauthenticated scans rely on network-visible services and banners, which miss registry-level patch data, OS configuration details, and installed updates. Authenticated scans with least-privilege credentials (e.g., using WMI, WinRM, or the Windows Update API) provide deep visibility into missing patches by querying the actual patch database (e.g., via the Microsoft Update Catalog or WSUS). This directly addresses the security manager's suspicion of missing patch data, making option C the correct choice.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.