CS0-003 Vulnerability Management Practice Question
A security analyst is configuring a vulnerability scanner for a new deployment. The scanner must be able to authenticate to targets to perform deep configuration audits against CIS Benchmarks. Which type of scan should the analyst configure?
⚠ Common exam trap
CS0-004 often tests the confusion between credentialed vs. external scans — candidates pick 'external' thinking it implies deep access, when external describes vantage point and credentialed describes authentication depth required for CIS Benchmark audits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Credentialed scan
A credentialed scan supplies valid credentials (e.g., SSH keys, SMB accounts, or API tokens) to the scanner, allowing it to log into targets and inspect local configuration, registry settings, file permissions, and patch levels. This deep access is required to audit against CIS Benchmarks, which specify OS and application configuration hardening checks that cannot be assessed externally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Credentialed scan
Why this is correct
Credentialed scans utilize valid administrative or user credentials to log directly into target systems, enabling the scanner to inspect local registries, installed software versions, and configuration files. This deep visibility allows for the identification of missing patches and misconfigurations that are invisible from the network perspective, minimizing false positives and negatives.
- ✗
Unauthenticated scan
Why it's wrong here
Unauthenticated scans probe target systems solely from across the network without login privileges, relying on open ports and banner grabbing to infer vulnerabilities. While useful for mapping the external attack surface, they cannot access internal system configurations, local patch registries, or file systems, resulting in a high rate of false positives and missed internal vulnerabilities.
- ✗
Passive scan
Why it's wrong here
Passive scanning relies on network sniffing and traffic analysis to identify active hosts, operating systems, and protocols without sending any packets to the targets. Because it does not actively query or log into systems, it cannot verify specific patch levels, registry settings, or local configuration vulnerabilities, making it unsuitable for comprehensive compliance or configuration audits.
- ✗
External scan
Why it's wrong here
External scans originate from outside the perimeter firewall to assess the organization's public-facing assets and perimeter defenses. Because these scans simulate an external attacker, they are typically blocked by firewalls from accessing internal resources and lack the local system access required to perform comprehensive configuration and patch audits on internal hosts.
Go deeper
Related to this question
Learn chapter
Cloud Vulnerability Management
Key term
Vulnerability scanner
A vulnerability scanner is an automated tool that identifies security weaknesses in systems, networks, and applications by comparing their configurations and software versions against known vulnerability databases.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.