Courseiva

CCNA Vulnerability Scanning Questions

22 questions · Vulnerability Scanning · All types, answers revealed

1
MCQmedium

A penetration tester is using Nessus to scan a large subnet and needs to avoid overwhelming older printers that are known to crash when too many simultaneous connections are made. The tester also wants to ensure the scan completes in a reasonable timeframe. Which Nessus scan policy setting should be adjusted to control the number of simultaneous hosts being scanned?

A.Reduce parallel checks per host
B.Scan window size
C.Max concurrent hosts
D.Max concurrent checks per host
AnswerC

Max concurrent hosts determines how many hosts are scanned at the same time. By reducing this value, the tester limits the number of devices being probed simultaneously, which directly lowers the risk of overwhelming fragile printers. It also helps manage overall network load while still allowing the scan to proceed efficiently.

Why this answer

The Max concurrent hosts setting directly controls how many hosts are scanned at the same time. Lowering this value ensures that fewer devices are probed concurrently, reducing the chance of crashing sensitive equipment like older printers. It balances scan speed with safety, making it the appropriate adjustment for the scenario.

Exam trap

The trap here is confusing per-host concurrency limits with global host concurrency, leading to a setting that doesn't actually reduce the number of simultaneous targets.

2
Multi-Selectmedium

A penetration tester is preparing to run a credentialed vulnerability scan against a mixed environment of Windows Server 2019 and Ubuntu 20.04 hosts on an internal /24 subnet. The tester wants to reduce scan duration and network load while still detecting missing patches and misconfigurations. Which two scanning techniques should the tester implement to achieve these goals? (Choose two.)

Select 2 answers
A.Use SSH and SMB credentials to allow the scanner to query the local patch database and installed software inventory.
B.Configure the scanner to perform a SYN stealth scan on all 65,535 TCP ports for every host before authenticating.
C.Limit the scan to a predefined list of common ports and disable all plugin families except 'Denial of Service'.
D.Enable local security checks on the scan policy and provide administrative credentials for each target.
E.Set the scanner to use a very aggressive timing template to maximize parallelism across all hosts.
AnswersA, D

Providing SSH and SMB credentials enables authenticated checks that query local patch databases and software inventories directly. This yields accurate detection of missing patches and misconfigurations while minimizing network probes, thereby reducing scan duration and load. It is a core technique for credentialed scanning in mixed Windows and Linux environments.

Why this answer

Credentialed scanning with local security checks is the most efficient way to detect missing patches and misconfigurations while minimizing network traffic and scan time. Supplying administrative credentials for Windows and SSH credentials for Linux allows the scanner to read local patch databases and software inventories directly, avoiding extensive remote probing. This approach improves accuracy and reduces load compared to unauthenticated or overly aggressive scanning methods.

Exam trap

The trap here is assuming that increasing scan aggressiveness or port coverage will speed up results, when in fact credentialed local checks are what reduce duration and network load while improving patch detection.

3
MCQeasy

A penetration tester has completed an unauthenticated vulnerability scan of a web server and received a report listing several critical CVEs. Before including these in the final report, the tester wants to validate that the findings are not false positives. Which action is the MOST appropriate next step?

A.Lower the scan's severity threshold and rescan to see if more issues appear.
B.Re-run the scan with a different scanner and compare results.
C.Manually verify the finding by checking the actual service version and testing the vulnerability.
D.Assume the scanner is correct and include the finding as critical.
AnswerC

Manual verification, such as banner grabbing, checking file versions, or safely reproducing the vulnerability, provides definitive proof. Scanners infer vulnerabilities from version strings or indirect indicators, which can be wrong. By directly inspecting the service and testing the specific issue, the tester eliminates false positives and can confidently report the finding with evidence.

Why this answer

Manual verification is the gold standard for confirming scanner findings. By directly checking the service version, inspecting configuration, or safely testing the vulnerability, the tester obtains evidence that the issue is real. This eliminates false positives and ensures the report is accurate.

Other options either do not validate the specific finding or risk reporting unverified critical issues.

Exam trap

The trap here is thinking that rescanning or using another tool validates a finding, when only direct manual confirmation proves the vulnerability exists.

4
MCQmedium

Which phase of a vulnerability assessment typically involves comparing the output against a known database of CVEs?

A.Host Discovery
B.Service Identification
C.Vulnerability Detection
D.Remediation Verification
AnswerC

Vulnerability detection is the phase where the scanner maps the software versions identified on the target against its internal CVE database. This process identifies known flaws associated with those specific versions and generates the reports that security teams use for remediation and risk prioritization.

Why this answer

After performing reconnaissance and data collection, the scanner matches discovered software versions and configurations against a vulnerability database. This matching phase is where the raw data is translated into actionable information. Understanding this is crucial because it highlights that the scanner's efficacy is strictly tied to the quality and recency of its signature database, which must be updated regularly to identify modern threats.

Exam trap

Candidates often confuse the 'Vulnerability Detection' phase with 'Reconnaissance' or 'Reporting'. They fail to recognize that the actual matching of CVEs occurs only after data collection.

5
MCQhard

During a vulnerability scan of a web application, the scanner reports a critical SQL injection vulnerability on a login form. A manual test using a single quote in the username field returns a generic error page with no database details. The scanner's evidence shows a time-based blind SQL injection payload that caused a five-second delay. Which action should the penetration tester take next to validate the finding?

A.Immediately report the SQL injection as a confirmed critical finding based on the scanner's time-based evidence.
B.Re-run the scanner with the same payload multiple times and compare the response times to confirm the delay is consistent.
C.Submit the login form with a benign username and password to check if the application returns a different error, then conclude the vulnerability is a false positive.
D.Manually inject a time-based payload that includes a conditional delay, such as '; IF (1=1) WAITFOR DELAY '0:0:5'--, and compare response times with a false condition.
AnswerD

Using a conditional time-based payload allows the tester to compare response times between true and false conditions. A consistent delay only when the condition is true confirms the injection point and rules out incidental latency. This is the standard manual validation technique for time-based blind SQL injection, providing strong evidence.

Why this answer

The most reliable way to confirm time-based blind SQL injection is to use a conditional payload that delays only when a true condition is met, and compare that with a false condition. This controls for network and server latency, demonstrating that the delay is caused by the injected SQL logic. Simply re-running the scanner or relying on a single delay is insufficient for validation.

Exam trap

The trap here is treating a single scanner-reported time delay as definitive proof, when blind SQL injection requires conditional testing to distinguish injection from incidental latency.

6
MCQeasy

What is the primary purpose of a 'delta' or 'differential' vulnerability scan?

A.To increase the intensity of the scan to ensure all ports are covered.
B.To identify only the changes in the vulnerability posture since the last scan.
C.To bypass signature-based detection systems by using randomized payloads.
D.To perform an exhaustive search for zero-day vulnerabilities on all assets.
AnswerB

Differential scans compare the results of the current scan to a baseline, highlighting only what has been added, removed, or changed. This allows administrators to track new vulnerabilities introduced by recent updates or configuration changes without wasting resources re-scanning systems that have not changed state.

Why this answer

Delta scans focus on identifying changes in the environment since the last full assessment. By comparing current findings against a known baseline, testers can quickly isolate new vulnerabilities or unauthorized changes. This is vital for maintaining a continuous security posture, as it reduces scan times and allows security teams to prioritize remediation efforts on newly introduced risks without re-analyzing the entire stable environment.

Exam trap

Candidates often confuse delta scans with full vulnerability audits, mistakenly believing they are meant to discover all vulnerabilities rather than specifically focusing on identifying changes since the last assessment.

7
MCQmedium

A penetration tester is conducting a vulnerability scan against a web application and notices that the scanner reports a critical SQL injection vulnerability on a page that does not accept user input. The tester manually verifies the page and finds no input fields or parameters. What is the most likely cause of this false positive?

A.The scanner is using an outdated vulnerability database.
B.The scanner is configured to perform blind SQL injection tests by injecting payloads into HTTP headers.
C.The scanner is using a safe checks policy that skips destructive tests.
D.The scanner is unable to authenticate to the web application.
AnswerB

Some scanners test for SQL injection by injecting payloads into HTTP headers such as User-Agent or Referer, even if the page has no user input. If the application logs these headers into a database without proper sanitization, the scanner might detect a vulnerability. This can cause a false positive if the page itself is not vulnerable but the logging mechanism is, or if the scanner misinterprets the response.

Why this answer

The most likely cause is that the scanner injects payloads into HTTP headers, which the application may log into a database. If the logging is vulnerable, the scanner could detect SQL injection even though the page itself has no input. This is a common source of false positives in web application scanning.

Other options do not explain why a false positive would occur on a page with no user input.

Exam trap

The trap here is assuming that a page with no input cannot be vulnerable, overlooking that scanners may test HTTP headers or other vectors that are not visible in the UI.

8
Multi-Selecthard

A penetration tester is planning a vulnerability scan of a network that includes legacy systems and IoT devices. The tester needs to minimize the risk of disrupting these fragile devices while still gathering useful vulnerability data. Which two actions should the tester take? (Choose two.)

Select 2 answers
A.Configure the scanner to throttle network traffic and reduce the number of concurrent hosts scanned.
B.Increase the scan's maximum number of concurrent checks per host to speed up the scan.
C.Enable 'Safe checks' in the scan policy to avoid tests that could cause denial-of-service.
D.Use a TCP SYN scan instead of a TCP connect scan to reduce the number of packets sent.
E.Disable host discovery and scan all IP addresses in the range.
AnswersA, C

Throttling and reducing concurrency lower the load on the network and target devices. This helps prevent overwhelming legacy systems and IoT devices, which may have low bandwidth or processing power. By pacing the scan, the tester can avoid disruptions while still collecting vulnerability data over a longer period.

Why this answer

Enabling safe checks and throttling network traffic are the two actions that directly reduce the risk of disrupting legacy systems and IoT devices. Safe checks avoid potentially harmful tests, while throttling and reduced concurrency prevent overwhelming devices with too much traffic. The other options either increase load, broaden the scan unnecessarily, or do not address the specific fragility of these devices.

Exam trap

The trap here is thinking that increasing concurrency or using a SYN scan will speed things up without considering the impact on fragile devices; the key is to throttle and use safe checks.

9
MCQhard

A penetration tester is using Nmap with the NSE script 'vulners' to identify vulnerabilities on a target. The scan returns a list of CVEs for detected services, but the tester notices that some CVEs have a low confidence score. What is the MOST accurate interpretation of these low-confidence findings?

A.They indicate that the CVE is not in the NVD database and is therefore invalid.
B.They indicate that the vulnerability is likely a false positive and should be ignored.
C.They are potential matches based on version correlation and should be manually verified before reporting.
D.They represent vulnerabilities that require authentication to exploit and are therefore lower risk.
AnswerC

The vulners NSE script correlates detected service versions with CVE databases. A low confidence score means the match is approximate, often due to version string ambiguity or missing patch information. These findings are leads that require manual verification, such as checking the exact build or testing the vulnerability, before being included in a report.

Why this answer

Low confidence in vulners output signals an approximate version-to-CVE match. Because service banners can be incomplete or versions backported, the script cannot be certain the vulnerability exists. The correct response is to treat these as potential findings and manually verify the service's exact version and patch state before reporting.

This avoids both false positives and false negatives.

Exam trap

The trap here is equating low confidence with false positive, when it actually means the version match is uncertain and needs verification.

10
MCQmedium

A penetration tester needs to scan a large enterprise network for vulnerabilities but has only a short maintenance window. The tester wants to maximize scan coverage while minimizing the impact on production systems. Which Nessus scan policy setting should the tester adjust to balance speed and accuracy?

A.Enable 'Safe checks' to prevent denial-of-service conditions.
B.Increase the 'Max concurrent checks per host' value.
C.Disable 'Thorough tests' to reduce scan time.
D.Adjust the 'Performance' settings to use a 'Custom' scan with optimized timeouts and throttling.
AnswerD

Custom performance settings allow fine-tuning of timeouts, throttling, and concurrent checks to balance speed and accuracy. This enables the tester to complete the scan within the window while reducing false negatives caused by timeouts. It is the most flexible approach to meet both coverage and impact constraints in a production environment.

Why this answer

The correct answer involves adjusting performance settings to a custom configuration. This allows the tester to optimize timeouts, throttling, and concurrency to complete the scan within the maintenance window while maintaining sufficient accuracy. Other options either focus solely on safety, risk disruption, or reduce coverage, failing to balance speed and accuracy as required.

Exam trap

The trap here is assuming that enabling 'Safe checks' or increasing concurrency alone will balance speed and accuracy, when in fact a custom performance profile is needed for fine-grained control.

11
MCQmedium

Refer to the exhibit. An Nmap scan returns output indicating a web server is responding, but the `http-enum` script fails to identify common directories. Which action should the tester take to improve detection?

A.Increase the timing template to -T5 to make the scan faster.
B.Add the --script-args='http-enum.basepath=/admin' argument to the command.
C.Use a specialized web discovery tool like ffuf or Gobuster with a large wordlist.
D.Change the scan to -sS to perform a stealthy SYN scan instead of service detection.
AnswerC

Nmap's http-enum script uses a relatively small, hardcoded wordlist. Dedicated tools like Gobuster or ffuf allow for custom, extensive wordlists and high-concurrency requests, which are far more effective at discovering hidden web directories that Nmap scripts would overlook in a standard scan.

Why this answer

The current command lacks service-specific depth. Adding a more comprehensive script category or using a specialized tool like Dirbuster or Burp Suite allows for brute-forcing against common file paths. Service version detection and enumeration scripts in Nmap are limited by the wordlist provided.

Improving detection requires moving beyond passive enumeration into active path discovery, which is essential for identifying hidden administrative interfaces or unlinked configuration files.

Exam trap

Candidates assume Nmap's default scripts are exhaustive. They often suggest running more Nmap scripts, failing to realize that specialized tools are required for effective web directory brute-forcing.

12
MCQhard

During a penetration test, a tester runs an OpenVAS scan against a web server and receives a report indicating a high-severity vulnerability with a CVE identifier. Before including it in the final report, the tester wants to verify if the vulnerability is actually exploitable. Which action should the tester take next?

A.Manually test the vulnerability using a proof-of-concept exploit or crafted request.
B.Check the CVE details in the National Vulnerability Database (NVD).
C.Review the scanner's plugin documentation to understand the detection logic.
D.Re-run the scan with a different scanner to confirm the finding.
AnswerA

Manually testing with a PoC or crafted request provides direct evidence of exploitability. It confirms whether the vulnerability is real and can be triggered in the target environment, which is essential for an accurate penetration test report. This step distinguishes between theoretical findings and actual risk.

Why this answer

Manual testing with a proof-of-concept or crafted request is the most reliable way to verify that a reported vulnerability is exploitable. It provides concrete evidence, reduces false positives, and ensures the finding is accurate before reporting. Other actions may offer context but do not directly confirm exploitability.

Exam trap

The trap here is assuming that a CVE match from a scanner automatically means the target is vulnerable, when in fact manual validation is needed to confirm exploitability.

13
MCQmedium

Which of the following actions is the most appropriate step after discovering a critical vulnerability that is currently being exploited in the wild?

A.Wait until the full scan report is generated at the end of the month.
B.Notify the system owners and trigger an out-of-band remediation process.
C.Re-run the scan to verify the vulnerability is not a false positive.
D.Isolate the server from the network immediately without notifying anyone.
AnswerB

Actively exploited vulnerabilities require immediate attention. Notifying the owners and initiating an out-of-band remediation process bypasses standard, slower reporting cycles, allowing for rapid patching or the implementation of temporary compensating controls to block exploitation attempts while the permanent fix is tested and deployed.

Why this answer

Immediate risk mitigation is required for vulnerabilities actively exploited in the wild. This involves prioritizing remediation and documenting the findings. Following standard vulnerability management practices ensures that the highest risks are addressed first, which is essential to minimize the window of exposure.

Waiting for a formal report before taking action on actively exploited vulnerabilities could result in a successful compromise of the organization's infrastructure.

Exam trap

Candidates often choose 'wait for the final report' as the correct action. In a professional setting, critical vulnerabilities being actively exploited require immediate out-of-band communication, not report-based delays.

14
MCQeasy

A penetration tester is configuring a vulnerability scanner to assess a sensitive production network. The tester wants to avoid causing service disruptions or overwhelming network devices. Which scanner setting should be adjusted to best achieve this?

A.Disable all plugin families except those that perform denial-of-service testing to quickly identify weak points.
B.Set the scanner to use a random port order and maximum timing template to evade detection.
C.Increase the maximum number of concurrent hosts and checks per host to finish faster.
D.Enable safe checks and reduce the scan's performance settings to limit simultaneous connections.
AnswerD

Safe checks avoid plugins known to disrupt services, and lowering performance settings reduces concurrent connections and packet rate. This combination minimizes the risk of overwhelming network devices or causing service outages. It is the standard approach for scanning sensitive production environments where availability is critical.

Why this answer

To avoid disrupting a sensitive production network, the scanner should be configured with safe checks enabled and performance settings lowered to reduce concurrent connections and packet rate. This minimizes the risk of overwhelming devices or causing service outages. Disabling DoS plugins and avoiding aggressive timing are also important, but safe checks and reduced performance are the primary controls.

Exam trap

The trap here is equating speed or stealth with safety, when in production environments the priority is limiting concurrency and avoiding intrusive checks.

15
MCQhard

A penetration tester is using Nmap to scan a target subnet and wants to identify all hosts that are up without performing port scanning. The tester also wants to avoid sending TCP SYN packets to reduce noise. Which Nmap option should the tester use?

A.-sS
B.-sn
C.-sP
D.-Pn
AnswerB

The -sn option performs a ping scan (host discovery) without port scanning. It sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default, but it does not perform a full port scan. This meets the requirement to identify live hosts without port scanning, though it may still send some TCP packets depending on the target's response.

Why this answer

The -sn option is designed for host discovery only, performing a ping scan without port scanning. It sends various probes to determine if hosts are up, but does not scan ports, thus reducing noise from TCP SYN packets to ports. Other options either perform port scanning, are deprecated, or skip discovery entirely, making them unsuitable for the scenario.

Exam trap

The trap here is confusing -sn with -Pn or -sS; -sn does host discovery without port scanning, while -Pn skips discovery and scans ports, and -sS is a port scan itself.

16
MCQeasy

A penetration tester is reviewing the results of a vulnerability scan and sees a finding labeled 'SSL Certificate Expired' on a web server. The tester confirms that the certificate is indeed expired. What is the most appropriate next step according to typical penetration testing methodology?

A.Document the finding, verify its impact, and include it in the final report with remediation recommendations.
B.Attempt to renew the certificate yourself to fix the issue.
C.Immediately exploit the expired certificate to gain unauthorized access.
D.Ignore the finding because expired certificates are not security vulnerabilities.
AnswerA

Penetration testing methodology involves validating findings, assessing their impact, and reporting them with remediation advice. An expired certificate is a configuration issue that can affect user trust and compliance, but it is not typically exploitable. Documenting it and recommending renewal is the correct next step.

Why this answer

The appropriate next step is to document the finding, verify its impact, and include it in the report with remediation recommendations. Expired certificates are configuration issues that can affect security and compliance but are not typically exploitable. The tester should not attempt to exploit or fix the issue unless authorized.

Ignoring it would be improper as it is a valid finding.

Exam trap

The trap here is thinking that an expired certificate is directly exploitable or that it should be ignored; it is a reportable misconfiguration, not an exploit vector.

17
MCQeasy

Which document should a penetration tester consult to determine the allowed scope and rules of engagement for a vulnerability scan?

A.The organization's public-facing bug bounty program policy.
B.The Rules of Engagement (RoE) document.
C.The vendor's hardware specification sheets.
D.The latest version of the Common Vulnerabilities and Exposures (CVE) list.
AnswerB

The Rules of Engagement document outlines the authorized scope, permitted testing times, and specific constraints for the engagement. It is the primary legal and operational guide that dictates how the tester can interact with the client's assets during a vulnerability assessment.

Why this answer

The Rules of Engagement (RoE) or Statement of Work (SOW) defines the legal and operational boundaries of the assessment. It specifies which systems are in scope, which are out of scope, and what scanning techniques are permitted. Adhering to these documents is essential for maintaining compliance and avoiding unauthorized actions that could lead to legal repercussions or unintended service disruption during the testing phase.

Exam trap

Candidates often confuse the Rules of Engagement with technical configuration guides or general security policies like a vulnerability management policy, forgetting that RoE specifically governs the operational boundaries and legal permissions for testing.

18
MCQhard

A penetration tester is using Nmap to scan a target network and wants to identify open UDP ports. The tester runs a UDP scan but notices that many ports are reported as 'open|filtered'. Which technique can help determine whether these ports are actually open or filtered?

A.Use a TCP ACK scan to infer UDP port states.
B.Perform a TCP SYN scan on the same ports.
C.Run a UDP scan with a longer timeout and more retries.
D.Send a UDP packet with a known payload and analyze the response.
AnswerD

Sending a UDP packet with a payload that elicits a response from a specific service can help differentiate open ports from filtered ones. If a service is listening, it may reply with an ICMP port unreachable or a protocol-specific response. This technique is more reliable than relying on generic UDP probes.

Why this answer

Sending a UDP packet with a known payload that triggers a response from a specific service can help determine if a port is open. If the service responds, the port is open; if no response or an ICMP unreachable is received, it may be filtered. This active probing provides more definitive results than generic scans.

Exam trap

The trap here is thinking that increasing timeout or retries will resolve the 'open|filtered' state, when in fact it only addresses packet loss, not the ambiguity between open and filtered.

19
Multi-Selectmedium

A penetration tester is analyzing the results of a vulnerability scan and needs to prioritize remediation efforts. Which two factors should be considered when determining the criticality of a vulnerability? (Choose two.)

Select 2 answers
A.The potential impact on the business if exploited
B.The age of the vulnerability in the CVE database
C.The CVSS base score of the vulnerability
D.The number of other vulnerabilities on the same host
E.The scanner's confidence level in the finding
AnswersA, C

Business impact is crucial because a vulnerability with a moderate CVSS score might be critical if it affects a key asset or sensitive data. Understanding the business context helps prioritize remediation that aligns with organizational risk appetite and compliance requirements.

Why this answer

CVSS base score and business impact are key factors for prioritizing vulnerabilities. CVSS provides a standardized severity metric, while business impact ensures that remediation efforts focus on what matters most to the organization. Together, they help balance technical severity with real-world consequences.

Exam trap

The trap here is overemphasizing technical metrics like CVSS without considering business context, or vice versa, leading to misprioritization.

20
MCQmedium

A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?

A.Configure the scanner to use the Domain Administrator account for full registry access.
B.Use a local account with no password to allow quick automated authentication.
C.Create a dedicated service account with granular WMI and remote registry permissions.
D.Store credentials in plain text in the scanner configuration file for easier automation.
AnswerC

Dedicated accounts with restricted permissions ensure that the scanner can query the necessary system information without broad administrative access. By limiting the scope of the account to WMI and registry read access, you maintain effective scan quality while significantly reducing overall risk.

Why this answer

Using dedicated, low-privilege service accounts with specific WMI and registry permissions minimizes the blast radius if credentials are intercepted. This approach adheres to the principle of least privilege, preventing the scanner from having full domain administrator access, which could be abused if the scanning server is compromised. Effective vulnerability management relies on deep system visibility without granting excessive authority to the scanning service.

Exam trap

Candidates often choose 'Domain Admin' credentials for ease of scanning, failing to realize that this violates the principle of least privilege and significantly increases risk during a security assessment.

21
Multi-Selecthard

A penetration tester is configuring a vulnerability scan against a large enterprise network. The tester needs to balance scan accuracy, speed, and impact on production systems. Which TWO of the following settings, when adjusted, will MOST directly reduce the risk of disrupting fragile network devices during the scan? (Choose two.)

Select 2 answers
A.Enable 'Safe Checks' in the scan policy.
B.Increase the maximum number of concurrent hosts scanned.
C.Reduce the scan's 'Max checks per host' value.
D.Disable 'Thorough tests' in the scan policy.
E.Set the scanner to use UDP instead of TCP for all checks.
AnswersA, C

Safe Checks prevents Nessus from running plugins that could crash services or devices, such as certain denial-of-service tests. On fragile devices like printers, VoIP phones, or legacy SCADA components, this setting avoids intrusive probes that might cause reboots or hangs. It directly reduces disruption risk while still allowing most vulnerability detection to proceed, making it a primary control for protecting production uptime.

Why this answer

The two settings that most directly reduce disruption are Safe Checks and Max checks per host. Safe Checks excludes plugins known to potentially crash services, while lowering Max checks per host throttles concurrent probes to each target. Together they limit both the type and the rate of intrusive traffic, protecting fragile production devices.

Other options either increase load or do not specifically target device stability.

Exam trap

The trap here is confusing scan depth settings like thorough tests with safety controls, when the real disruption risk comes from unsafe plugins and high concurrency.

22
MCQmedium

A penetration tester is preparing to scan a network that includes a mix of traditional IT systems and industrial control systems (ICS). The tester wants to minimize the risk of disrupting ICS devices. Which scanning approach is MOST appropriate for the ICS segment?

A.Perform an aggressive Nmap scan with OS detection and version scanning.
B.Use a passive scanner that only listens to network traffic without sending packets.
C.Scan the ICS segment during a planned maintenance window with Safe Checks enabled.
D.Run a credentialed scan with default settings to get the most accurate results.
AnswerB

Passive scanning monitors existing traffic to identify devices and vulnerabilities without injecting any packets. This eliminates the risk of disrupting ICS devices, which may be sensitive to unexpected probes. Tools like Tenable Nessus Passive Scanner or Wireshark with protocol dissectors can inventory assets and detect issues. It is the safest approach for fragile OT environments where uptime is critical.

Why this answer

Passive scanning is the safest method for ICS because it does not send any traffic that could disrupt fragile devices. It relies on observing existing network traffic to identify assets and potential vulnerabilities. Active scanning, even with Safe Checks or during maintenance, carries inherent risk of causing outages.

For OT environments, passive monitoring is the recommended first step before any active testing.

Exam trap

The trap here is assuming that Safe Checks or a maintenance window makes active scanning safe for ICS, when only passive monitoring guarantees no disruption.

Ready to test yourself?

Try a timed practice session using only Vulnerability Scanning questions.