CISSP Security Assessment and Testing Practice Question
Which TWO of the following are benefits of authenticated vulnerability scanning compared to unauthenticated scanning?
⚠ Common exam trap
CISSP often tests the misconception that authenticated scanning is 'quieter' or 'faster' — in reality it is deeper and heavier, and the exam expects you to recognize that its primary benefits are visibility and accuracy, not traffic reduction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Can detect vulnerabilities that require valid credentials to be seen
Option A is correct because authenticated scanning logs into the target host with valid credentials, allowing the scanner to inspect local files, registry keys, installed packages, and configuration settings that are invisible to an unauthenticated scan, thereby detecting vulnerabilities that require credentials to be seen. Option D is correct because credentialed access lets the scanner read exact software versions, patch levels, and update history directly from the host, yielding more accurate patch-level information than remote banner grabbing or version inference. Option B is not correct because authenticated scans typically generate more traffic, not less, since they perform deeper enumeration and local checks. Option C is not correct because no scanning method eliminates false positives entirely; authentication reduces but does not remove them. Option E is not correct because authenticated scans still require network access to reach and log into the target host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Can detect vulnerabilities that require valid credentials to be seen
Why this is correct
Authenticated scans operate with valid credentials, allowing them to access the internal configuration, file systems, and running processes of a target system. This deep access enables the detection of vulnerabilities that are only visible post-authentication, such as misconfigurations in internal services, insecure file permissions, or unpatched software versions that an unauthenticated scan might miss entirely.
- ✗
Reduces network traffic
Why it's wrong here
Authenticated vulnerability scans typically generate *more* network traffic, not less. By logging into systems, the scanner performs deeper, more granular checks, querying system configurations, installed software, patch levels, and file permissions directly. This extensive data collection and interaction with the target system's internal state inherently requires more network communication than a superficial, unauthenticated scan that only probes external services.
- ✗
Eliminates false positives entirely
Why it's wrong here
While authenticated scans significantly reduce false positives compared to unauthenticated scans due to their ability to verify actual patch levels and configurations, they do not eliminate them entirely. False positives can still arise from misinterpretations of system data, incomplete vulnerability definitions, or environmental factors that lead the scanner to incorrectly flag a non-vulnerable condition as a risk. No automated scanning technology can guarantee 100% accuracy.
- ✓
Provides more accurate patch-level information
Why this is correct
Authenticated vulnerability scans provide significantly more accurate patch-level information because they can directly query the operating system and installed applications for their exact version numbers and installed updates. By logging in, the scanner can access system registries, package managers, or file system metadata to confirm whether specific security patches have been successfully applied, rather than relying on less reliable banner grabbing or service fingerprinting. This direct verification reduces uncertainty and improves remediation prioritization.
- ✗
Does not require network access
Why it's wrong here
Authenticated vulnerability scans absolutely require network access to the target systems. While they use credentials to gain deeper access *within* the system, the initial connection, credential transmission, and subsequent data exchange between the scanner and the target all occur over the network. The scanner needs to communicate with the target's operating system or management agents to perform its checks, making network connectivity a fundamental prerequisite.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.