CS0-003 Security Operations Practice Question
A security analyst is configuring a vulnerability scanner for internal network scanning. The analyst wants to ensure the scanner can identify missing patches and software configurations that require administrative privileges to read. Which scan type should the analyst configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Credentialed scan
Credentialed scans use administrative credentials to access systems and retrieve detailed configuration information, including missing patches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Non-credentialed scan
Why it's wrong here
A non-credentialed scan probes target systems from the network perspective without administrative privileges. While useful for mapping the external attack surface and identifying exposed services, it cannot query the local registry, package manager, or file system to verify specific patch levels or internal configuration settings. This limitation leads to a high rate of false negatives regarding local vulnerabilities.
- ✓
Credentialed scan
Why this is correct
A credentialed scan utilizes provided administrative or user credentials to log directly into the target operating system. This allows the scanner to perform deep local inspections, such as querying the registry, checking package manager databases, and auditing configuration files. Consequently, it provides a highly accurate assessment of missing patches and misconfigurations with minimal false positives.
- ✗
External scan
Why it's wrong here
An external scan originates from outside the organization's security perimeter, simulating what an internet-based attacker can see. It is primarily designed to evaluate firewall rules, perimeter defenses, and publicly accessible services rather than auditing internal host configurations. It lacks the network positioning and access rights required to perform a comprehensive patch and vulnerability assessment on internal assets.
- ✗
Passive scan
Why it's wrong here
A passive scan monitors network traffic via a SPAN port or network TAP to identify active hosts, protocols, and potential vulnerabilities based on observed packet headers and payloads. Because it does not actively query or interact with the target hosts, it cannot inspect local file systems, registry keys, or software version metadata. This makes it incapable of reliably verifying patch levels or deep system configurations.
Go deeper
Related to this question
Learn chapter
Privileged Access Management and PAM Tools
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.