CS0-003 Security Operations Practice Question
A security analyst is performing a vulnerability scan on an internal network. The analyst wants to ensure the scanner can identify vulnerabilities in applications that require authentication. Which TWO scan configurations should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Agent-based scan
Credentialed scans allow the scanner to authenticate to systems and perform deeper checks, while authenticated scans (agent-based) can also provide access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scan with default credentials
Why it's wrong here
Scanning with default credentials relies on factory-set usernames and passwords, which only identifies whether those specific defaults remain active. It does not grant the comprehensive administrative access required to audit local registry keys, installed software patches, or deep system configurations. Furthermore, relying on default credentials poses a severe security risk and does not represent a structured, authenticated vulnerability assessment methodology.
- ✗
Non-credentialed scan
Why it's wrong here
A non-credentialed scan inspects the target from the perspective of an unauthenticated outsider, analyzing open ports, banners, and exposed network services. Because it lacks local system access, it cannot inspect the local registry, file system permissions, or missing software patches. This approach results in a high rate of false negatives for internal vulnerabilities that are not exposed directly to the network.
- ✓
Agent-based scan
Why this is correct
Agent-based scans utilize a lightweight software package installed directly on the target endpoint to perform local, authenticated assessments. This method eliminates the need to manage network credentials or open inbound ports, allowing the agent to execute with local system privileges. It is highly effective for transient assets, such as remote laptops, which may not be consistently connected to the corporate network during scheduled network scans.
- ✗
External scan
Why it's wrong here
External scans originate from outside the network perimeter to evaluate the organization's public-facing attack surface, such as firewalls and public IP addresses. They are incapable of bypassing perimeter defenses to perform deep, authenticated internal audits of endpoint operating systems. Consequently, they cannot provide visibility into local software vulnerabilities, misconfigured internal services, or registry-level security gaps.
- ✓
Credentialed scan
Why this is correct
Credentialed scans use provided administrative or user-level credentials to log into target systems over the network, allowing the scanner to perform deep, authenticated audits. This approach enables the scanner to query the registry, inspect the file system, and verify installed patches without installing local software. While highly thorough, it requires robust credential management and network connectivity between the scanner and the target.
Go deeper
Related to this question
Learn chapter
Container and Kubernetes Security Analysis
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.