CS0-003 Security Operations Practice Question
A security team is configuring a vulnerability scanner for external scanning of their public-facing web applications. Which scan type will provide the most accurate assessment of vulnerabilities without requiring credentials?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
External scan
An external scan assesses the attack surface from the internet perspective, typically without credentials. Agent-based and authenticated scans require credentials or internal access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
External scan
Why this is correct
External scans are conducted from outside the organization's network perimeter, directly simulating the perspective of an external attacker targeting public-facing assets. This approach identifies exposed ports, misconfigured firewalls, and unpatched vulnerabilities in public web applications without requiring internal network access or system credentials.
- ✗
Agent-based scan
Why it's wrong here
Agent-based scanning relies on software agents installed locally on target endpoints to collect vulnerability data from within the operating system. This method is unsuitable for assessing external perimeter defenses or public web applications from an outsider's perspective, as it bypasses network-level security controls and requires administrative access to install the agent.
- ✗
Authenticated scan
Why it's wrong here
Authenticated (or credentialed) scans require valid system or application credentials to log in and perform a deep, inside-out assessment of local configurations and patch levels. While highly thorough for internal audits, this approach does not accurately replicate the initial reconnaissance and exploitation phase of an unauthenticated external threat actor.
- ✗
Internal scan
Why it's wrong here
Internal scans originate from a scanner placed inside the local network, behind the perimeter firewalls and intrusion prevention systems. This setup is designed to identify lateral movement paths and internal vulnerabilities, making it ineffective for evaluating how external-facing assets appear to attackers on the public internet.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Attack surface
The attack surface is the total sum of all points in a system, network, or application where an unauthorized user can try to enter or extract data.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.