Courseiva

CISSP Security Assessment and Testing Practice Question

Which TWO of the following are benefits of authenticated vulnerability scanning compared to unauthenticated scanning?

⚠ Common exam trap

CISSP often tests the misconception that authenticated scanning is 'quieter' or 'faster' — in reality it is deeper and heavier, and the exam expects you to recognize that its primary benefits are visibility and accuracy, not traffic reduction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Can detect vulnerabilities that require valid credentials to be seen

Option A is correct because authenticated scanning logs into the target host with valid credentials, allowing the scanner to inspect local files, registry keys, installed packages, and configuration settings that are invisible to an unauthenticated scan, thereby detecting vulnerabilities that require credentials to be seen. Option D is correct because credentialed access lets the scanner read exact software versions, patch levels, and update history directly from the host, yielding more accurate patch-level information than remote banner grabbing or version inference. Option B is not correct because authenticated scans typically generate more traffic, not less, since they perform deeper enumeration and local checks. Option C is not correct because no scanning method eliminates false positives entirely; authentication reduces but does not remove them. Option E is not correct because authenticated scans still require network access to reach and log into the target host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Can detect vulnerabilities that require valid credentials to be seen

    Why this is correct

    Authenticated scans operate with valid credentials, allowing them to access the internal configuration, file systems, and running processes of a target system. This deep access enables the detection of vulnerabilities that are only visible post-authentication, such as misconfigurations in internal services, insecure file permissions, or unpatched software versions that an unauthenticated scan might miss entirely.

  • ✗

    Reduces network traffic

    Why it's wrong here

    Authenticated vulnerability scans typically generate *more* network traffic, not less. By logging into systems, the scanner performs deeper, more granular checks, querying system configurations, installed software, patch levels, and file permissions directly. This extensive data collection and interaction with the target system's internal state inherently requires more network communication than a superficial, unauthenticated scan that only probes external services.

  • ✗

    Eliminates false positives entirely

    Why it's wrong here

    While authenticated scans significantly reduce false positives compared to unauthenticated scans due to their ability to verify actual patch levels and configurations, they do not eliminate them entirely. False positives can still arise from misinterpretations of system data, incomplete vulnerability definitions, or environmental factors that lead the scanner to incorrectly flag a non-vulnerable condition as a risk. No automated scanning technology can guarantee 100% accuracy.

  • ✓

    Provides more accurate patch-level information

    Why this is correct

    Authenticated vulnerability scans provide significantly more accurate patch-level information because they can directly query the operating system and installed applications for their exact version numbers and installed updates. By logging in, the scanner can access system registries, package managers, or file system metadata to confirm whether specific security patches have been successfully applied, rather than relying on less reliable banner grabbing or service fingerprinting. This direct verification reduces uncertainty and improves remediation prioritization.

  • ✗

    Does not require network access

    Why it's wrong here

    Authenticated vulnerability scans absolutely require network access to the target systems. While they use credentials to gain deeper access *within* the system, the initial connection, credential transmission, and subsequent data exchange between the scanner and the target all occur over the network. The scanner needs to communicate with the target's operating system or management agents to perform its checks, making network connectivity a fundamental prerequisite.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.