Courseiva
Security Assessment and TestingmediumMultiple ChoiceObjective-mapped

CISSP Security Assessment and Testing Practice Question

Which type of scanning provides the most comprehensive view of an organization's vulnerabilities by allowing the scanner to log into systems and access detailed configuration information?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Authenticated scan

Authenticated scans use credentials to access system internals, providing deeper insight than unauthenticated scans.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • External scan

    Why it's wrong here

    An external scan is inherently limited as it simulates an attack from outside the network perimeter, typically without any credentials. While crucial for identifying internet-facing vulnerabilities and misconfigurations, it cannot access internal system configurations, patch levels, or vulnerabilities that are only exploitable from within the network or with authenticated access. Therefore, it provides only a perimeter-level view, not a comprehensive internal assessment.

  • Passive scan

    Why it's wrong here

    Passive scanning involves monitoring network traffic and system behavior without actively sending probes or interacting with the target system. This method is excellent for detecting anomalies, exposed services, or misconfigurations that manifest in network communications, but it cannot actively discover hidden vulnerabilities, unpatched software, or internal configuration weaknesses that do not generate observable network traffic. Its non-intrusive nature means it lacks the depth of active, direct system inspection.

  • Authenticated scan

    Why this is correct

    An authenticated scan provides the most comprehensive view because it operates with legitimate user credentials, allowing it to log into target systems and inspect their internal configurations, patch levels, installed software, and user permissions directly. This privileged access enables the scanner to identify vulnerabilities that are only detectable from within the operating system or application, such as missing security updates, insecure registry settings, or weak file permissions, offering a true internal security posture assessment.

  • Unauthenticated scan

    Why it's wrong here

    An unauthenticated scan simulates an attacker with no prior knowledge or access credentials, probing network services and applications from an external perspective. While effective for identifying publicly exposed vulnerabilities and misconfigurations visible from the network perimeter, it cannot delve into the internal workings of a system. This limitation means it will miss critical vulnerabilities residing within the operating system, applications, or databases that require authenticated access to detect, thus providing an incomplete security picture.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.