Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

You are performing a vulnerability scan on an internal network using an authenticated scanner. Which of the following is a primary benefit of authenticated scanning compared to unauthenticated scanning?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It provides more accurate identification of vulnerabilities that require credentials

Authenticated scanning provides deeper insight by checking for missing patches, misconfigurations, and vulnerabilities that require valid credentials to detect, such as local privilege escalation issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It eliminates false positives entirely

    Why it's wrong here

    No scanning methodology can guarantee the complete absence of false positives. Even with valid credentials, a scanner can misinterpret configuration states, encounter incomplete patch data, or match vulnerability signatures incorrectly, leading to reported issues that do not actually exist under the specific deployment context. Authenticated scanning reduces this noise by inspecting local system state, but it does not eliminate the possibility of erroneous findings.

  • ✗

    It reduces network traffic

    Why it's wrong here

    Authenticated scanning typically increases network traffic rather than reducing it. The scan must first complete authentication handshakes, negotiate protocols, and maintain sessions for each target, then it often queries additional endpoints (registry, file system, services) that unauthenticated scans would not touch. This added communication can create a larger network footprint, especially in environments with many hosts.

  • ✓

    It provides more accurate identification of vulnerabilities that require credentials

    Why this is correct

    With valid credentials, the scanner can log in to the target and perform local checks, such as inspecting installed patches, configuration files, running services, and file permissions, rather than relying solely on remote banner grabbing and version inference. This enables the scanner to identify vulnerabilities that only manifest post-authentication, such as weak local security policies or missing cumulative updates, with far greater accuracy.

  • ✗

    It avoids detection by intrusion detection systems

    Why it's wrong here

    Authenticated scans are not designed to evade intrusion detection; they can still be detected by IDS/IPS through patterns like repeated login attempts, unusual account usage, or the execution of scanner-related commands. Many IDS rules specifically flag credentialed scanning activities because they may resemble account compromise or lateral movement, and the scanner's privileged access can trigger alarms.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.