Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is configuring a vulnerability scanner for internal network scanning. The analyst wants to ensure the scanner can identify missing patches and software configurations that require administrative privileges to read. Which scan type should the analyst configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Credentialed scan

Credentialed scans use administrative credentials to access systems and retrieve detailed configuration information, including missing patches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Non-credentialed scan

    Why it's wrong here

    A non-credentialed scan probes target systems from the network perspective without administrative privileges. While useful for mapping the external attack surface and identifying exposed services, it cannot query the local registry, package manager, or file system to verify specific patch levels or internal configuration settings. This limitation leads to a high rate of false negatives regarding local vulnerabilities.

  • ✓

    Credentialed scan

    Why this is correct

    A credentialed scan utilizes provided administrative or user credentials to log directly into the target operating system. This allows the scanner to perform deep local inspections, such as querying the registry, checking package manager databases, and auditing configuration files. Consequently, it provides a highly accurate assessment of missing patches and misconfigurations with minimal false positives.

  • ✗

    External scan

    Why it's wrong here

    An external scan originates from outside the organization's security perimeter, simulating what an internet-based attacker can see. It is primarily designed to evaluate firewall rules, perimeter defenses, and publicly accessible services rather than auditing internal host configurations. It lacks the network positioning and access rights required to perform a comprehensive patch and vulnerability assessment on internal assets.

  • ✗

    Passive scan

    Why it's wrong here

    A passive scan monitors network traffic via a SPAN port or network TAP to identify active hosts, protocols, and potential vulnerabilities based on observed packet headers and payloads. Because it does not actively query or interact with the target hosts, it cannot inspect local file systems, registry keys, or software version metadata. This makes it incapable of reliably verifying patch levels or deep system configurations.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.