Courseiva

GSEC Practice Question: Vulnerability Scanning and Penetration Testing

A security consultant is configuring a Tenable Nessus scan to assess a mixed environment of Windows and Linux servers. The consultant needs to ensure the scan can authenticate to targets and perform local checks without relying on agent installation. Which two Nessus scan settings should the consultant configure to provide credentials for authenticated scanning? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any credential type enables authenticated scanning, when Nessus uses specific protocols like SSH and SMB for host-based checks on Linux and Windows respectively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSH credentials for Linux hosts

Authenticated scanning in Nessus for a mixed environment requires SSH credentials for Linux hosts and SMB credentials for Windows hosts. These allow the scanner to log in and perform local checks, increasing accuracy. Other credential types are for network devices or databases and do not fulfill the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Kerberos ticket for domain authentication

    Why it's wrong here

    Nessus does not directly accept Kerberos tickets as a credential type for authenticated scanning. While Windows authentication may involve Kerberos behind the scenes, the scanner expects username and password or hash credentials via SMB. Providing a Kerberos ticket alone is not a supported configuration method in Nessus for host-based checks.

  • ✓

    SSH credentials for Linux hosts

    Why this is correct

    Nessus uses SSH credentials to log into Linux and Unix hosts and run local commands for patch level, configuration, and vulnerability checks. Without valid SSH credentials, the scan falls back to unauthenticated checks, which are less accurate. Configuring SSH credentials is essential for authenticated scanning of Linux systems in a mixed environment.

  • ✗

    Database credentials for SQL Server instances

    Why it's wrong here

    Database credentials are used for specialized database vulnerability checks, such as auditing SQL Server configurations and permissions. They do not enable operating system-level authenticated scanning of Windows or Linux hosts. The question asks for credentials to perform local checks on servers, which requires SSH and SMB, not database logins.

  • ✗

    SNMP community strings for network devices

    Why it's wrong here

    SNMP community strings are used to query network devices such as routers, switches, and printers for configuration and interface information. While useful for scanning network infrastructure, SNMP credentials do not provide authenticated access to Windows or Linux servers for local vulnerability checks. They are not part of the credential set for server operating system scanning.

  • ✓

    SMB credentials for Windows hosts

    Why this is correct

    For Windows targets, Nessus uses SMB credentials to authenticate and perform local checks via remote registry, file system access, and WMI queries. Providing SMB credentials enables Nessus to detect missing patches, insecure configurations, and other host-based vulnerabilities that are invisible to unauthenticated scans. This is a core requirement for authenticated Windows scanning.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.