CISSP Security Assessment and Testing Practice Question
Which type of scanning provides the most comprehensive view of an organization's vulnerabilities by allowing the scanner to log into systems and access detailed configuration information?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authenticated scan
Authenticated scans use credentials to access system internals, providing deeper insight than unauthenticated scans.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
External scan
Why it's wrong here
An external scan is inherently limited as it simulates an attack from outside the network perimeter, typically without any credentials. While crucial for identifying internet-facing vulnerabilities and misconfigurations, it cannot access internal system configurations, patch levels, or vulnerabilities that are only exploitable from within the network or with authenticated access. Therefore, it provides only a perimeter-level view, not a comprehensive internal assessment.
- ✗
Passive scan
Why it's wrong here
Passive scanning involves monitoring network traffic and system behavior without actively sending probes or interacting with the target system. This method is excellent for detecting anomalies, exposed services, or misconfigurations that manifest in network communications, but it cannot actively discover hidden vulnerabilities, unpatched software, or internal configuration weaknesses that do not generate observable network traffic. Its non-intrusive nature means it lacks the depth of active, direct system inspection.
- ✓
Authenticated scan
Why this is correct
An authenticated scan provides the most comprehensive view because it operates with legitimate user credentials, allowing it to log into target systems and inspect their internal configurations, patch levels, installed software, and user permissions directly. This privileged access enables the scanner to identify vulnerabilities that are only detectable from within the operating system or application, such as missing security updates, insecure registry settings, or weak file permissions, offering a true internal security posture assessment.
- ✗
Unauthenticated scan
Why it's wrong here
An unauthenticated scan simulates an attacker with no prior knowledge or access credentials, probing network services and applications from an external perspective. While effective for identifying publicly exposed vulnerabilities and misconfigurations visible from the network perimeter, it cannot delve into the internal workings of a system. This limitation means it will miss critical vulnerabilities residing within the operating system, applications, or databases that require authenticated access to detect, thus providing an incomplete security picture.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.