PT0-002 Reconnaissance and Enumeration Practice Question
You are performing a vulnerability scan on an internal network using an authenticated scanner. Which of the following is a primary benefit of authenticated scanning compared to unauthenticated scanning?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It provides more accurate identification of vulnerabilities that require credentials
Authenticated scanning provides deeper insight by checking for missing patches, misconfigurations, and vulnerabilities that require valid credentials to detect, such as local privilege escalation issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It eliminates false positives entirely
Why it's wrong here
No scanning methodology can guarantee the complete absence of false positives. Even with valid credentials, a scanner can misinterpret configuration states, encounter incomplete patch data, or match vulnerability signatures incorrectly, leading to reported issues that do not actually exist under the specific deployment context. Authenticated scanning reduces this noise by inspecting local system state, but it does not eliminate the possibility of erroneous findings.
- ✗
It reduces network traffic
Why it's wrong here
Authenticated scanning typically increases network traffic rather than reducing it. The scan must first complete authentication handshakes, negotiate protocols, and maintain sessions for each target, then it often queries additional endpoints (registry, file system, services) that unauthenticated scans would not touch. This added communication can create a larger network footprint, especially in environments with many hosts.
- ✓
It provides more accurate identification of vulnerabilities that require credentials
Why this is correct
With valid credentials, the scanner can log in to the target and perform local checks, such as inspecting installed patches, configuration files, running services, and file permissions, rather than relying solely on remote banner grabbing and version inference. This enables the scanner to identify vulnerabilities that only manifest post-authentication, such as weak local security policies or missing cumulative updates, with far greater accuracy.
- ✗
It avoids detection by intrusion detection systems
Why it's wrong here
Authenticated scans are not designed to evade intrusion detection; they can still be detected by IDS/IPS through patterns like repeated login attempts, unusual account usage, or the execution of scanner-related commands. Many IDS rules specifically flag credentialed scanning activities because they may resemble account compromise or lateral movement, and the scanner's privileged access can trigger alarms.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.