Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is using OpenVAS to perform an authenticated vulnerability scan of a Linux server. The tester has provided valid SSH credentials. Which of the following is a primary benefit of performing an authenticated scan over an unauthenticated scan?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ability to detect vulnerabilities that require local access

Authenticated scans have deeper access to the system, allowing the scanner to check configuration files, patch levels, and local vulnerabilities that are not visible externally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ability to detect vulnerabilities that require local access

    Why this is correct

    Authenticated scanning leverages valid credentials to log into the target OS and perform local checks, such as inspecting file permissions, registry keys, installed software versions, and missing security patches. These truly local vulnerabilities are invisible to unauthenticated network-based scans, which can only observe remotely reachable services and banners. This credential-based access is the primary technical justification for choosing an authenticated scan.

  • ✗

    Reduced network bandwidth usage

    Why it's wrong here

    Authenticated scans do not reduce network bandwidth usage; in fact, they often consume more bandwidth because the scanner must transfer additional execution modules, retrieve local file metadata, and sometimes download updated vulnerability databases during the scan. The bandwidth cost is roughly the same or higher, and the real advantage of authenticated scanning is the depth of visibility, not network efficiency.

  • ✗

    Faster scan completion time

    Why it's wrong here

    Authenticated scans typically run longer than unauthenticated scans, not faster. With credentials, the scanner can enumerate local applications, audit patch levels, and run complex configuration checks across the entire system, all of which add extra time to the scan window. A faster completion time is not a benefit of authenticated scanning.

  • ✗

    Elimination of all false positives

    Why it's wrong here

    While credentialed access reduces the incidence of false positives by replacing guesswork with definitive local state checks, it cannot eliminate them entirely. False positives persist due to scanner plugin bugs, ambiguous version strings, non-standard system configurations, and situations where the target's environment does not exactly match the check's assumptions. Elimination of all false positives is therefore an unattainable claim for any scanning method.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.