Triage BoardGet the app

Domain 2 · Vulnerability Management

Choosing the right vulnerability scanning method

Choosing a vulnerability scanning method means deciding which scan to run, from where and when. Objective 2.1 hands you a network, a constraint and a goal, and the right answer comes from three settled facts: what is on the network, what each system can tolerate, and which view of it (insider, outsider, logged-in) the question needs.

  • Exam code CS0-004
  • Domain weight 26%
  • Tickets here 16

The 2.1 task list

  • Start from an asset inventory and know how discovery scans fill its gaps
  • Plan around scheduling, operations, performance, sensitivity levels, segmentation and regulatory requirements
  • Choose the scan type on four separate axes: internal or external, agent or agentless, credentialed or non-credentialed, passive or active
  • Tell a mapping scan from device fingerprinting
  • Run security baseline scans against the Payment Card Industry Data Security Standard (PCI DSS), Center for Internet Security (CIS) Benchmarks or the ISO 27000 series

Planning comes before the first packet

Objective 2.1 is a given a scenario objective (CS0-004 objectives, version 2.0, checked October 2026), so most items describe a real constraint and test whether your plan respects it. The planning considerations go in this order:

Scheduling and operations

A scan window has to fit around backups, batch jobs, change freezes and the people who will take the calls if something slows down. When the stem mentions a business calendar, the schedule is part of the answer.

Performance and sensitivity levels

Scanners use bandwidth on the wire and CPU on the target. You trade speed for stability with fewer hosts in parallel, lower rate limits and smaller check sets. Sensitivity levels decide how intrusive the checks are, from safe checks that only read banners to tests that can knock over a fragile service. Older appliances, printers and operational technology get the gentlest profile.

Segmentation and regulatory requirements

A firewall between scanner and target changes what the scanner sees, so a segmented network needs a scanner or agents inside each zone. Regulation sets some of the rules for you. PCI DSS requires external scans of the cardholder data environment by an Approved Scanning Vendor (PCI DSS v4.0.1 requirement 11.3, checked October 2026), on top of the internal scans your own team runs.

Asset inventory

Every one of these choices assumes you know what you own. An inventory records each asset's owner, its exposure and how critical it is, and those three fields drive the scan type, the window and the profile. Cloud workloads and containers come and go between scans, which is why discovery runs on a schedule of its own.

Four axes, chosen one at a time

Scan types in CS0-004 objective 2.1: each axis is independent of the others
AxisOne endOther endWhat decides it
Internal vs externalInside the perimeter: the view after a footholdFrom the internet: the view any outsider hasWhose exposure the stem asks about
Agent vs agentlessSoftware on the host reports in, even off-networkScanner reaches over the network, nothing installedWhether hosts are reachable when the scan runs
Credentialed vs non-credentialedLogs in and reads patch levels and local configSees only what services exposeDepth and fewer false positives, or the outsider's view
Passive vs activeWatches traffic and sends no probesSends probes and reads the repliesHow much the targets can tolerate

Credentialed scanning has its own page: credentialed vs non-credentialed vulnerability scans.

The scan cycle

AssetinventoryDiscoveryscanmapping,fingerprintsPlan thewindowload, timing,rulesScantype set peraxisBaselinecheckPCI DSS, CIS,ISO
Discovery feeds new assets back into the inventory, so each cycle scans what the last one found.

Credentialed is not the same as intrusiveTrap

A credentialed scan logs in and reads, which can be gentler on a service than an unauthenticated scan that probes it from outside. Intrusiveness comes from the checks you enable, the sensitivity level, and that is a separate setting. When a stem says a scan must not disturb a host, look for the answer in the profile and the schedule. Whether the scanner has a password is a different question.

Mapping, fingerprinting and baselines

Discovery comes in two depths. A mapping scan shows what is alive and how it connects: hosts, subnets, open ports. Device fingerprinting goes a step further and identifies what each device is (operating system, service version, device type) from the way it answers. Fingerprinting turns "something on 192.0.2.40 answers on 443" into "an appliance running an old web server", and a vulnerability check needs that second version.

A baseline scan compares configuration against a published standard, so it is not hunting for CVE entries. The objective names three standards. PCI DSS applies to systems that store, process or transmit cardholder data. The CIS Benchmarks are hardened configuration guides for each product. The ISO 27000 series is the family of standards around ISO/IEC 27001 information security management. A baseline finding reads "this setting does not match the benchmark".

Reading what the scanners return is the next objective, analyzing assessment tool output. Deciding what to fix first comes after that, in prioritizing and mitigating vulnerabilities.

Scan-planning tickets

Start from the constraint in each stem (a scan window, a fragile host, a regulation) and build the plan around it.

Ticket 1 / 16

0 right

INC-001

When establishing a vulnerability management program, what should be the first step?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: you cannot scan, prioritize or protect assets you do not know exist, so asset inventory and discovery come first.
  2. BTools come after you know the scope; buying a scanner first risks one that does not fit the environment.
  3. CException policies govern findings that cannot be fixed, which only matters once scanning is producing findings.
  4. DRemediation procedures depend on knowing which assets and vulnerabilities exist, so they come later.

INC-002

Which factor is MOST important to consider when determining the scanning frequency for different systems within an organization?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. APhysical location rarely changes how likely or how damaging a compromise is, so it is not the main driver of frequency.
  2. BThe OS vendor affects which checks run, not how often a system needs to be scanned.
  3. CAge can hint at legacy risk, but a new internet-facing critical system still needs more frequent scans than an old isolated one.
  4. DCorrect: scanning frequency should follow risk, so critical and exposed systems get scanned most often.

INC-003

Which regulatory framework has specific requirements for vulnerability scanning frequency in cardholder data environments?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AHIPAA requires risk analysis and safeguards for health data but sets no scanning frequency or cardholder rules.
  2. BCorrect: PCI DSS (Requirement 11.3 in v4.0.1) requires internal and external vulnerability scans at least quarterly and after significant changes, with external scans by an Approved Scanning Vendor (ASV).
  3. CSOX governs controls over financial reporting and does not prescribe vulnerability scanning intervals.
  4. DGDPR requires appropriate security for personal data in general terms, without a scan frequency or any cardholder-specific scope.

INC-004

An organization implemented asset tagging to align vulnerability scanning schedules with business risk. Reviewing the following asset groups, which schedule is misconfigured and creates a significant blind spot?

Exhibit

Asset GroupCriticalityExposureCurrent Scan Frequency
Payment ProcessingHighInternalWeekly
Public Web FrontendsHighInternet-FacingQuarterly
Archival StorageLowInternalMonthly
Dev WorkstationsMediumInternalWeekly

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AWeekly scanning of medium-criticality workstations is more than enough, so it is not a blind spot; cutting it to quarterly would add risk.
  2. BWeekly scans of internal payment systems are reasonable, and continuous scanning is not required to avoid a blind spot.
  3. CCorrect: internet-facing, high-criticality frontends scanned only quarterly can carry new exposures for months, which is the real gap.
  4. DLow-criticality systems should be scanned less often, not removed from scanning; excluding them would create a blind spot.

INC-005

Given the network segments and business constraints below, which scan scheduling approach minimizes performance impact?

Exhibit

SegmentHostsBandwidthCriticalityMaintenance Window
Core20010 GbpsHigh02:00-04:00
DMZ501 GbpsMedium22:00-02:00
OT30100 MbpsCriticalNone

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: throttling bandwidth and batching Core hosts inside their 02:00–04:00 window keeps load low when the business is least affected.
  2. BScanning every segment at full speed at once maximizes load and can saturate the 100 Mbps OT link.
  3. CAn unthrottled DMZ scan in business hours ignores its 22:00–02:00 window and hits users when traffic is highest.
  4. DRandom full scans with no time limits ignore the maintenance windows and can hit critical systems at peak times.

INC-006

An organization plans to run intrusive vulnerability scans against critical infrastructure. Which governance elements must be defined in the scanning policy before execution?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. APublishing findings within 24 hours exposes unpatched weaknesses to attackers and is not a governance requirement.
  2. BDaily full scans regardless of asset class ignore the fragility of critical infrastructure and maximize disruption.
  3. CRemediating without testing or maintenance windows adds outage risk instead of governing the scan.
  4. DCorrect: intrusive scans of critical infrastructure need an approval workflow, exception tracking and a rollback plan defined before anyone runs them.

INC-007

A vulnerability scan report lacks metadata on the profile, credentials, and timing used. Which governance change best enables future reproduction and validation of findings?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AThe change board handles changes to systems and cannot supply the missing scan metadata that makes findings impossible to reproduce.
  2. BFinal PDFs keep the results but not the profile, credential set and timing needed to rerun the scan the same way.
  3. CManual remediation notes record what was fixed but not how the scan was configured, so findings still cannot be reproduced.
  4. DCorrect: a policy that retains the scan profile, the credential set used (not the secrets themselves in the report) and timing lets anyone rerun and validate the same scan.

INC-008

What action should be taken when a vulnerability scan disrupts a critical production system?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. APermanently excluding a critical system creates a blind spot; the scan settings should be fixed instead.
  2. BCorrect: stop the scan to limit damage, then identify which checks caused the disruption so future scans can be tuned rather than dropped.
  3. CLetting the scan continue keeps damaging a critical production system.
  4. DPatching everything without testing is unrelated to the disruption and adds outage risk of its own.

INC-009

Before launching an attack, threat actors often automate the collection of system information. What is it called when attackers systematically gather details about operating systems and software versions?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: fingerprinting identifies operating systems, services and software versions, often automatically from banners and protocol responses.
  2. BDNS enumeration discovers hostnames and records in a domain and reveals nothing about OS or software versions.
  3. CPhishing tricks people into revealing information or running code; it is not systematic system profiling.
  4. DCredential stuffing replays leaked username and password pairs to break into accounts.

INC-010

Examine the vulnerability scan configurations and incident logs. Which scanning configuration most likely caused the documented denial of service incident on the industrial controller?

Exhibit

ProfileTargetAuthenticationIntensity Level
AWeb ServersEnabledAggressive (Default)
BDatabasesEnabledThrottled
CSCADA / PLCDisabledAggressive (Default)
DWorkstationsEnabledNormal

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Profile C runs an aggressive default scan against SCADA/PLC devices, which often cannot handle that traffic volume and crash.
  2. BAuthentication is actually disabled for the SCADA profile, and authenticated scanning tends to reduce network probing rather than cause a DoS.
  3. CProfile B is throttled and aimed at databases, so it never touched the industrial controller that failed.
  4. DProfile A is aggressive but targets web servers, which are built to handle that traffic and were not the device that failed.

INC-011

An organization manages Windows servers, Linux endpoints, cloud VMs, and offline laptops. Which scanning approach provides the best coverage with minimal network impact?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AAgentless scans need network reach, so they miss laptops that are offline or off the corporate network during the scan.
  2. BAgents on Windows servers alone leave Linux endpoints, cloud VMs and laptops uncovered.
  3. CWeekly non-credentialed scans give only an outside view, miss offline laptops and add network load.
  4. DCorrect: agents cover endpoints and roaming laptops without network sweeps, while API integration covers cloud VMs, giving full coverage at low network cost.

INC-012

Discovery identified a legacy OT controller that crashes under aggressive scanning. Which scan settings and verification approach best balances coverage with stability?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AMaximum intensity during production hours is exactly what crashes the fragile controller.
  2. BA full credentialed scan with a production service account is not a gentler setting, and it exposes a privileged credential to the scan.
  3. CStandard intensity without lab testing still risks crashing a controller already known to be fragile.
  4. DCorrect: the lightest probe set, proven safe on an identical lab unit and then run in a maintenance window, gives coverage without risking the controller.

INC-013

What method can a cybersecurity analyst use to gather information on network vulnerabilities without interacting with the target system?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. APatch management deploys updates; it does not gather vulnerability information.
  2. BIntrusive scanning actively probes and may exploit the target, which is the opposite of non-interactive.
  3. CPenetration testing actively attacks the target to prove exploitability.
  4. DCorrect: passive scanning listens to existing network traffic to infer hosts, services and vulnerabilities without sending probes to the target.

INC-014

Which of the following is the BEST approach for conducting vulnerability assessments on Industrial Control Systems (ICS)?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ASkipping ICS assessment leaves critical systems unassessed, which is a governance failure dressed up as a safety measure.
  2. BCorrect: ICS-aware tools understand industrial protocols and fragile devices, and scheduling with approval keeps operations safe.
  3. CFull penetration testing on every ICS component risks outages and physical safety issues.
  4. DStandard IT scans during production hours can disrupt controllers and halt physical processes.

INC-015

When conducting vulnerability scans in a containerized environment, which approach is MOST effective?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: image scans catch flaws before deployment, and runtime scans catch drift, configuration issues and containers built from old images.
  2. BRegistry-only scanning misses running containers that drifted or were deployed from older images.
  3. CRuntime-only scanning finds problems after they are already in production and misses images waiting to be deployed.
  4. DScanning only the host OS misses the libraries and packages inside the container images.

INC-016

When implementing vulnerability scanning for multiple compliance frameworks (PCI DSS, HIPAA, SOC 2), what is the most efficient approach?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ASeparate scans per framework duplicate effort and can produce inconsistent results for the same systems.
  2. BAlternating frameworks leaves each one unmet for most of the year and breaks requirements such as quarterly PCI DSS scans.
  3. CScanning for one framework leaves the others out of compliance.
  4. DCorrect: one program built to the strictest requirement of each framework satisfies all of them with a single, consistent process.

Shift tally

0 / 0

The scanning plan in five lines

  • Inventory and discovery decide what gets scanned. An incomplete inventory leaves blind spots no scan setting can fix.
  • Choose each axis on its own: vantage, agent, credentials, passive or active.
  • Intrusiveness is a profile setting and has nothing to do with credentials.
  • Baseline scans measure configuration against PCI DSS, CIS Benchmarks or ISO 27000.
  • Vulnerability Management is 26% of CS0-004 (CS0-004 objectives, version 2.0, checked October 2026).

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.