PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is using OpenVAS to perform an authenticated vulnerability scan of a Linux server. The tester has provided valid SSH credentials. Which of the following is a primary benefit of performing an authenticated scan over an unauthenticated scan?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ability to detect vulnerabilities that require local access
Authenticated scans have deeper access to the system, allowing the scanner to check configuration files, patch levels, and local vulnerabilities that are not visible externally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ability to detect vulnerabilities that require local access
Why this is correct
Authenticated scanning leverages valid credentials to log into the target OS and perform local checks, such as inspecting file permissions, registry keys, installed software versions, and missing security patches. These truly local vulnerabilities are invisible to unauthenticated network-based scans, which can only observe remotely reachable services and banners. This credential-based access is the primary technical justification for choosing an authenticated scan.
- ✗
Reduced network bandwidth usage
Why it's wrong here
Authenticated scans do not reduce network bandwidth usage; in fact, they often consume more bandwidth because the scanner must transfer additional execution modules, retrieve local file metadata, and sometimes download updated vulnerability databases during the scan. The bandwidth cost is roughly the same or higher, and the real advantage of authenticated scanning is the depth of visibility, not network efficiency.
- ✗
Faster scan completion time
Why it's wrong here
Authenticated scans typically run longer than unauthenticated scans, not faster. With credentials, the scanner can enumerate local applications, audit patch levels, and run complex configuration checks across the entire system, all of which add extra time to the scan window. A faster completion time is not a benefit of authenticated scanning.
- ✗
Elimination of all false positives
Why it's wrong here
While credentialed access reduces the incidence of false positives by replacing guesswork with definitive local state checks, it cannot eliminate them entirely. False positives persist due to scanner plugin bugs, ambiguous version strings, non-standard system configurations, and situations where the target's environment does not exactly match the check's assumptions. Elimination of all false positives is therefore an unattainable claim for any scanning method.
Go deeper
Related to this question
Learn chapter
CVSS Scoring in Penetration Test Reports
Key term
Unauthenticated scan
An unauthenticated scan is a vulnerability assessment performed without providing valid login credentials, simulating an outside attacker's perspective.
Key term
Authenticated scan
An authenticated scan is a vulnerability scan that uses valid credentials to log into a system and examine it from the inside, providing a more thorough assessment of security weaknesses than an unauthenticated scan.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.