← Back

19 Vulnerability Scanning Methods Practice Questions & Answers

Every Vulnerability Scanning Methods practice question from the CompTIA CySA+ Practice Test, with the correct answer and a short explanation.

Start practice test →
  1. 1. A non-credentialed scan of a Linux web server returns 'HTTP service detected; version string suppressed' and lists three CVEs as potential findings. The team asks what a credentialed scan of the same host would change. Which statement is correct?

    • A.It authenticates to the host and reads installed package versions and configuration, so a finding rests on evidence instead of a banner guess.✓ Answer
    • B.It sends the same probes far more quickly, so more services answer inside the timeout and the potential findings are turned into confirmed ones.
    • C.It attempts to exploit each potential finding on the host, which is how an authenticated check proves that the vulnerability is really present.
    • D.It reaches the host from inside the perimeter, and that vantage point is what removes the potential qualifier from the plugin output.

    A credentialed scan logs in and queries the host's own package database, registry and configuration files, so the finding rests on the version and settings actually installed rather than on an inferred banner. That evidence is why authenticated scanning produces far fewer false positives and also exposes configuration weaknesses that no network probe can see. Credentialed checks do not exploit anything, and network position is a separate variable.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - credentialed vs. non-credentialed scanningReport a problem with this question

  2. 2. A field sales team's laptops connect to the corporate network only a few days a month and otherwise work from homes and hotels. Their vulnerability data is consistently more than a month old. Which collection method fits these hosts, and why?

    • A.Schedule a nightly network scan of the entire corporate wireless range, since roaming laptops re-register there and are captured when they connect.
    • B.Scan the remote-access address pool during business hours, because that range holds the current address of every laptop that is working away.
    • C.Raise the network scanner's timeout and retry count so that laptops which are asleep or away from the office still answer the probes in time.
    • D.Deploy a scanning agent to each laptop; it assesses the host locally and uploads results whenever the device has any internet path to the console.✓ Answer

    An agent assesses the host from the inside on its own schedule and reports to the console over any internet path, which is exactly what a device that is seldom on the corporate network needs. A network scan can only evaluate an address while the host is powered on, reachable and inside the declared scope, so it structurally misses roaming endpoints. No timeout or retry setting can reach a machine that is not on the network at all.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - agent-based vs. agentless scanningReport a problem with this question

  3. 3. On a plant network, the vendor documents that the programmable logic controllers may fault when they receive unexpected traffic, and the contract forbids active probing of them. The analyst must still obtain vulnerability information about these devices. Which approach fits, and what is its limitation?

    • A.Run the active policy with the dangerous plugins disabled and a single thread, since the lower intensity removes any risk of faulting a controller.
    • B.Analyse a mirrored copy of the segment's traffic to fingerprint protocols and firmware, which adds no packets but sees only devices that transmit.✓ Answer
    • C.Perform an authenticated scan of every controller with the vendor's engineering account, because authenticated checks send no unexpected traffic.
    • D.Schedule the active scan for the monthly shutdown window, because a controller that is powered down cannot be faulted by an unexpected packet.

    Passive observation of mirrored traffic identifies devices, protocols and software versions without injecting a single packet, which is why it is the accepted method for fragile operational technology that must not be touched. Its cost is coverage: a device that stays silent during the capture window never appears, and versions can only be inferred from what the protocol reveals. Reducing the intensity of an active scan lowers but does not remove the risk, and authenticating still means sending traffic the controller may not expect.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - passive vs. active scanningReport a problem with this question

  4. 4. A hospital's infusion pumps and imaging consoles are vendor-maintained, carry regulatory approval that forbids the hospital from altering their software, and have crashed during past port scans. Clinical engineering still owes the security committee a vulnerability picture for them. Which approach is appropriate?

    • A.Identify the devices passively and use vendor advisories for their component inventory, holding them in a restricted segment until fixes arrive.✓ Answer
    • B.Remove the clinical range from the programme, since the vendor's regulatory approval makes any finding the hospital records unusable anyway.
    • C.Sweep every device with a full port and service scan each quarter, which is light enough to be safe and still satisfies an external assessor.
    • D.Apply the standard authenticated server policy to them, because clinical devices are hosts much like any other and belong in the same monthly report.

    When sensitivity and fragility rule out active or authenticated scanning, the assessment is built from passive identification plus the vendor's own component and advisory information, and the residual risk is handled with compensating controls such as strict segmentation and monitoring. This keeps the devices in the vulnerability management programme without generating the traffic that has already crashed them. Dropping the range from the programme leaves a blind spot, and a quarterly full port sweep is exactly the activity the devices cannot tolerate.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - scanning considerations: sensitivity levels and operationsReport a problem with this question

  5. 5. A perimeter firewall permits only tcp/443 to a web server, which also listens internally on tcp/22 and tcp/1433. A scanner on the server's own subnet reports all three services; a scanner hosted outside the network reports only the HTTPS service. Which conclusion is correct?

    • A.The external result is wrong, because a scanner is expected to enumerate every listening port on a target whatever the network path to it may be.
    • B.Both results hold from their own vantage point: the external view measures what an internet attacker reaches, the internal view what is exposed inside.✓ Answer
    • C.The internal result is wrong, because findings on ports that the firewall blocks are false positives and have to be removed from the report.
    • D.The difference proves the firewall is misconfigured, since correct filtering makes internal and external scans of one host return the same list.

    A scan result is a statement about a path, not only about a host: the external perspective measures the attack surface actually reachable from the internet, while the internal perspective measures what an attacker or insider already inside the network would find. Both are needed, because the internal findings describe real exposure once the perimeter is bypassed, and the external findings describe today's reachable surface. Filtering is the expected reason the two differ, not evidence that either scan is faulty.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - internal vs. external scanningReport a problem with this question

  6. 6. A monthly scan of the documented address ranges reports that 98 percent of findings are remediated. An intrusion is then traced to a departmental file server that appears in no inventory and in no scan scope. What does the 98 percent figure actually tell the organization?

    • A.It remains valid for the estate as a whole, because the scan sweeps every live address it meets inside the documented ranges each month.
    • B.It shows the discovery settings were too aggressive, and the departmental server was folded into a known host as a duplicate entry.
    • C.It proves the remediation teams under-reported their work, since an estate that is fully patched cannot produce an incident from an unpatched host.
    • D.It describes only the hosts that were in scope, so an inventory that omits assets yields a figure that says nothing about the omitted ones.✓ Answer

    Asset inventory is the prerequisite for scanning: a scan can only speak about the addresses it was told to assess, so any remediation percentage is a statement about scope, not about the environment. An omitted asset is not reported as a gap, it is simply absent, which is why an incomplete inventory converts into false assurance. The fix is continuous discovery reconciled against the inventory so that scope and estate match.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - asset discovery and inventory as a scanning prerequisiteReport a problem with this question

  7. 7. A full authenticated scan of the virtual estate launched at 10:00 on a weekday saturated a hypervisor's CPU, and a trading application timed out. The business will not accept a repeat, and security must still cover the estate monthly. Which change to the scan setup meets both demands?

    • A.Keep the 10:00 schedule but drop the authenticated checks, since scanning without credentials places no measurable load on the systems tested.
    • B.Move the scan to an agreed low-activity window and cap concurrent hosts and checks per host, splitting the estate so all of it is covered monthly.✓ Answer
    • C.Reduce the scan to once a year at the same hour, which is the accepted way to balance monthly coverage against operational disruption.
    • D.Exclude the virtual estate and report physical servers only, recording the resulting gap in coverage as an accepted risk on the register.

    Scan planning balances coverage against operational impact through three levers the analyst controls: when the scan runs, how much of the estate it touches at once, and how hard it drives each target. Agreeing a low-activity window, throttling concurrency and splitting the estate into batches preserves monthly coverage while removing the load spike that broke the application. Dropping authentication reduces accuracy rather than load, and abandoning coverage converts an engineering problem into an unmanaged blind spot.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - scanning considerations: scheduling, operations and performanceReport a problem with this question

  8. 8. Developer laptops and auto-scaled cloud instances are frequently powered down during the 02:00 scan window. The scanner marks their addresses as not responding, and they disappear from the monthly report rather than appearing with findings. Which statement about this result is correct?

    • A.A host that is off during the window inherits its previous results, which is why the report carries it forward with no outstanding findings.
    • B.A host that is off during the window is safely left out, because a machine that is powered down cannot hold an exploitable vulnerability.
    • C.A host that is off during the window is simply not assessed, so its absence must be reconciled against the inventory rather than read as clean.✓ Answer
    • D.A host that is off during the window points to a broken scan policy, and the fix is to raise the plugin timeouts until the address answers again.

    An unreachable target produces no data, and no data is not the same as no vulnerabilities: the silence only means the host was outside the assessment at that moment. Because the report's denominator is what answered, coverage must be measured against the inventory, and hosts that are intermittently available are better served by agents or by scan windows aligned to when they run. Reading a missing host as clean is how an unpatched workstation stays invisible for months.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - scan scheduling and coverage reconciliationReport a problem with this question

  9. 9. A scanner in the datacenter core reports every host in a remote branch segment as having no open ports and no findings, although staff there use file and print services on those hosts all day. What is the most likely explanation, and the correct fix?

    • A.The scan used too few threads for a slow remote link, so raising the thread count will let the probes finish and reveal the listening ports.
    • B.The branch hosts each run a host firewall that blocks scans, so the empty result is accurate and that segment needs no further assessment.
    • C.The branch uses private addressing the scanner cannot route to, so those hosts have to be re-addressed into the range that the core uses.
    • D.An access list on the path is dropping the probes, so a scanner belongs inside that segment or the scanner's traffic must be permitted through it.✓ Answer

    When a filtering device sits between the scanner and the target, the probes never arrive and the scanner reports silence, which looks identical to a hardened host. A clean result that contradicts known running services is therefore a coverage failure, not a security achievement, and it is resolved by scanning from inside the segment or by an agreed exception for the scanner's path. Thread counts and addressing do not explain a whole segment answering nothing while users work on it.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - segmentation and scanner placementReport a problem with this question

  10. 10. A web application scan of a customer portal finishes in eight minutes and reports findings only on the marketing pages, the login page and the password-reset form. Account management, payments and administration all sit behind the login. What does the scan configuration need?

    • A.It needs a greater crawl depth and a higher request rate, which lets the unauthenticated crawler enumerate the functions behind the login form.
    • B.It needs a maintained session: credentials, a recorded login sequence and an excluded logout link, or the crawler never reaches the pages behind it.✓ Answer
    • C.It needs the network service plugins enabled, because post-login functions are discovered by port and service checks rather than by web checks.
    • D.It needs credentialed access to the web server host, because reading the application's source files on disk is how post-login pages are found.

    A web application scanner tests what its crawler can reach, and everything behind a login is unreachable unless the scan holds a valid session: supplied credentials, a login sequence it can replay, and logout or session-destroying links excluded so the session survives the crawl. Without that configuration the scan silently covers only the public surface, which is why an eight-minute run on a large portal is itself a warning sign. Crawl depth, network plugins and host credentials do not create an application session.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - web application scanning, authenticated crawlingReport a problem with this question

  11. 11. Authenticated host scans of the production container nodes report no findings for a payments service, yet that service's image was built on a base image containing a known vulnerable TLS library. Why did the host scan miss it, and what must be scanned?

    • A.Containers hide their own processes from the scanner, so the same host policy has to be re-run with root credentials in order to reveal the library.
    • B.The host policy inspects the node's own packages, not the layers inside the image, so images must be scanned in the build pipeline and registry.✓ Answer
    • C.The result is correct, because a library packaged inside a container image is unreachable by an attacker and is therefore not a real finding.
    • D.The host policy should be replaced by an external perimeter scan, which is the vantage point that exposes vulnerable components in an image.

    A host scan enumerates the packages the node's own operating system installed, while a container's dependencies live in the image layers the workload brings with it, so the vulnerable library is invisible from that vantage point. Container content is therefore assessed where it is produced and stored, by scanning images in the build pipeline and in the registry before deployment, and by tracking the components each image contains. The finding is real: code inside a running container executes and is reachable through the service it exposes.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - container image scanning in the build pipeline and registryReport a problem with this question

  12. 12. A pipeline scans infrastructure-as-code templates before apply and blocks any definition that grants public access. Three months later an audit finds a production database reachable from the internet, and no template declares that setting. What does this reveal about the scan's scope?

    • A.The template scan already covers the deployed environment continuously, so the audit finding means an exception was written into the policy rules.
    • B.The template scan replaces runtime cloud assessment once every resource is declared in code, so the finding shows the pipeline was bypassed.
    • C.The template scan judges only the declared configuration, so a console change stays invisible and the deployed state must be assessed as well.✓ Answer
    • D.The template scan cannot evaluate access settings at all, which is why an exposed database has to be found by an authenticated host scan.

    Scanning definitions before deployment catches insecure configuration early, but its evidence is the template, so anything changed afterwards by hand, by an operator in the provider console or by another automation simply is not in scope. Cloud security posture must therefore be assessed against the deployed state as well, so that drift away from the declared configuration is detected. The two placements answer different questions and neither replaces the other.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - infrastructure-as-code scanning and cloud configuration assessmentReport a problem with this question

  13. 13. One workstation appears in two reports: the network scan of its subnet lists four findings, and the scanning agent installed on it lists thirty-seven, including an outdated PDF reader and an unpatched browser. Which explanation of the difference is correct?

    • A.The agent reports software the user already removed, because its local database refreshes only when the laptop rejoins the corporate network.
    • B.The agent counts each issue twice, once per plugin family, which is what makes its total several times larger than the network scan's total.
    • C.The network scan is authoritative because it tests the host as an attacker would, so the extra agent findings are not real exposure at all.
    • D.The network scan can only judge services that listen on the network, while the agent enumerates installed software and patch state on local disk.✓ Answer

    The two methods observe different things: a network scan can only reason about ports, services and responses that cross the wire, while an agent reads the installed software inventory, patch level and configuration from inside the operating system. Client-side software such as document readers and browsers listens on nothing, so it is invisible to the network scan yet is a genuine exposure because users open untrusted content with it. Neither report is double counting, and the agent's findings are not retired software.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - agent-based vs. network-based collectionReport a problem with this question

  14. 14. A new analyst is told to scan the branch offices. There is no address documentation, no host list, and the network team can only supply the routed prefixes reachable over the wide area network. Which action comes first, and why?

    • A.Launch the full authenticated policy against every routed range at once, because the scan itself will assemble the asset list while it runs.
    • B.Ask each branch manager for a spreadsheet of devices and assess only what comes back, since a scan may only touch documented assets.
    • C.Run a discovery scan of the routed ranges to find live hosts and fingerprint their operating systems and services, which defines the scope.✓ Answer
    • D.Scan the public addresses of the branch firewalls first, because an external view of the perimeter substitutes for an internal host inventory.

    Discovery scanning is the step that converts address ranges into a known population: mapping scans find which addresses are live and fingerprinting identifies operating systems, services and roles, which is what allows a sensible scope, credential set and intensity to be chosen. Firing a full authenticated policy at unknown ranges risks disrupting fragile hosts and wastes effort on addresses nobody owns. A manager's spreadsheet is a useful cross-check, but shadow assets are precisely what it omits.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - discovery scanning: mapping scans and device fingerprintingReport a problem with this question

  15. 15. An assessor asks for evidence that production servers match the hardening benchmark the organization adopted. The team's monthly scan policy detects missing patches and known vulnerabilities only. Which change to the scan produces that evidence?

    • A.Run the scanner's configuration audit policy, comparing each host's settings against the chosen benchmark, since that is what measures a baseline.✓ Answer
    • B.Raise the severity threshold of the current policy so only critical entries appear, which is the form an assessor accepts as hardening evidence.
    • C.Re-run the current policy with credentials, because an authenticated vulnerability scan that returns nothing shows the baseline was applied.
    • D.Export twelve months of vulnerability trend data, since a falling finding count is the accepted proof that hosts match a hardening standard.

    Vulnerability detection and baseline or compliance scanning answer different questions: one asks whether known flaws are present, the other compares each host's settings item by item against a named configuration standard and reports the deviations. Only a configuration audit policy, run with credentials against the adopted benchmark, produces per-setting compliance evidence. An absence of vulnerability findings says nothing about password policy, service hardening, audit settings or permissions.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - security baseline scanning against a configuration standardReport a problem with this question

  16. 16. Security objects that the planned authenticated agentless scan of 2,000 servers requires domain-privileged credentials to be stored in the scanner and used across the network. Which statement about the agent-based alternative is accurate?

    • A.An agent needs no credentials because it only reads local network banners, which is why its output matches an unauthenticated network scan.
    • B.An agentless scan becomes credential-free once the deep configuration plugins are enabled, as those plugins read patch state without authenticating.
    • C.An agent runs with the host's own privileges, so no scanning credential crosses the network, at the cost of deploying software on every host.✓ Answer
    • D.An agent is not an option on servers, since agents are supported only on roaming user endpoints, so the credentials have to stay in the scanner.

    An agent already executes locally with the privileges it needs, so the authenticated depth of the assessment is obtained without distributing or transmitting a privileged scanning account, which removes a standing credential exposure. The trade-off is operational: software must be deployed, updated and monitored on every host, and platforms without an agent still need agentless coverage. Agents are supported on servers, and no plugin set reads installed patch state without authenticating.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - agent-based vs. agentless scanning trade-offsReport a problem with this question

  17. 17. A compliance mandate requires that every host in the segment handling payment card data be scanned. The scan policy pings each address first and skips anything that does not answer, and several hardened hosts in that segment drop ICMP. What must change?

    • A.Re-enable ICMP on the hardened hosts so the current discovery method works, which is the configuration the mandate expects of such systems.
    • B.Accept the gap and record the silent hosts as compliant, because a host that ignores ICMP presents no reachable service to an outside attacker.
    • C.Turn off ping-only host discovery, or add TCP and UDP discovery probes, so hosts that suppress ICMP are still assessed and counted in scope.✓ Answer
    • D.Move the scanner into the segment and keep ping discovery, since discovery failures come from network distance rather than from host settings.

    Host discovery settings decide which addresses ever get assessed, so a policy that treats an unanswered ICMP echo as an absent host silently excludes exactly the systems that were hardened. Adding TCP and UDP discovery probes, or disabling the ping prerequisite so listed addresses are always tested, restores the mandated coverage. Weakening a host's configuration to suit the scanner is the wrong direction, and the scanner's location does not change how it chooses to discover hosts.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - scanning considerations: regulatory requirements and scan scopeReport a problem with this question

  18. 18. A scan aimed at the published virtual address of a clustered application returns one host with a clean patch level. Six web nodes sit behind that address and are patched on different schedules. Which statement about the scan is correct?

    • A.Whichever member the balancer selected was assessed, so the nodes must also be scanned individually by their own addresses to cover the pool.✓ Answer
    • B.The result is sufficient, since a service published behind one virtual address exposes only the configuration the balancer itself terminates.
    • C.The pool was assessed as a unit, because the balancer forwards each probe to all of its members and merges their answers back to the scanner.
    • D.The result is void, because a balanced service can only be assessed by an agent on the balancer, which holds the patch state of the pool.

    A virtual address is a single logical target, and the balancer hands each connection to one member, so the report describes whichever node happened to serve the probes and silently generalises it to the whole pool. Because the members are patched on different schedules, coverage requires scanning each node by its own address, or collecting from agents on the members. This is the same class of configuration error as scanning a name that resolves to a proxy or content delivery edge instead of the origin.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - scan scope and target selection behind a virtual addressReport a problem with this question

  19. 19. Halfway through an internal scan, results stop arriving and the remaining hosts are recorded as unreachable. The inline prevention system's log shows that it classified the scanner's address as a scanning source and blocked it. How should this be handled?

    • A.Treat the results as incomplete, then arrange an allowlist entry or a scanner inside the segment so a blocking device does not shape coverage.✓ Answer
    • B.Accept the results as accurate, since hosts sitting behind a prevention system that blocks scanning have no exposure that is worth reporting.
    • C.Raise the scan rate so the probes finish before the prevention system reacts, which is the usual way to complete a scan through inline defences.
    • D.Disable blocking on the prevention system across all segments during working hours, so that every future scan completes without coordination.

    A scan that a defensive device cut short measures the device's reaction, not the hosts' exposure, so the run must be recorded as partial and repeated under conditions that let it complete, typically a coordinated exception for the scanner's address or a scanner placed inside the segment. Treating the truncated output as a clean result hides every unassessed host, since the blocked probes produce the same silence as a hardened one. Turning prevention off estate-wide trades a coverage problem for a real reduction in protection.

    Source: CompTIA CySA+ CS0-004 Objective 2.1 - scan coverage, network defences and coordinationReport a problem with this question

Practice questions based on the CompTIA CySA+ exam objectives. This site is not affiliated with or endorsed by CompTIA, and these are not real exam questions. CompTIA refreshes this exam periodically, runs two versions side by side during a transition, and sets the exam length, passing standard and eligibility terms — confirm the current objectives and the live exam code with CompTIA before you register. The real exam also includes performance-based items that a multiple-choice bank cannot reproduce, so pair this with hands-on practice. Official CySA+ exam objectives →