Courseiva
Securing AssetshardMultiple ChoiceObjective-mapped

CCOA Securing Assets Practice Question

You are performing a credentialed vulnerability scan using Nessus Professional on a Linux server. The scan reports that the 'Remote Windows SMB' service is missing patches, but the target is Linux. What is the most likely cause of this discrepancy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The Nessus scanner has performed a fingerprinting mismatch due to an incorrect 'Credentialed Patch Audit' policy setting.

This is a common issue when the 'Safe Checks' are enabled or when the SSH service is configured to allow legacy protocols that trigger incorrect plugin attribution in the vulnerability database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The scanner is configured to run 'Non-Credentialed' scans only, resulting in false positives.

    Why it's wrong here

    Non-credentialed scans typically do not return detailed patch-level vulnerabilities.

  • The Nessus scanner has performed a fingerprinting mismatch due to an incorrect 'Credentialed Patch Audit' policy setting.

    Why this is correct

    The vulnerability scan likely applied a Windows plugin set because the credentials provided or the SSH banner allowed for a misidentification of the OS family during the initial discovery phase.

  • The Linux server is hosting a Windows VM, and the scanner is reporting on the guest OS.

    Why it's wrong here

    Nessus scanners do not automatically cross-map guest OS vulnerabilities in this manner without specific hypervisor-level integration.

  • The Linux server has Samba installed, and the vulnerability scanner is correctly identifying a vulnerability in the SMB stack.

    Why it's wrong here

    While possible, reporting a 'Remote Windows SMB' service on a Linux target is a diagnostic error in the scan configuration rather than a legitimate service identification.

About these practice questions

One of 203 original CCOA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official ISACA exam blueprint

This CCOA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCOA exam.