Study. uk . com
  1. Home
  2. All questions
  3. Question 388

CISSP study material · question 388 of 500

A scanning programme produces shallow results and the team is considering credentialed scanning. What does SP 800-115 say about that approach?

  1. Some network-based scanners hold administrator credentials on the hosts and extract vulnerability information using them.
  2. Credentialed scanning is prohibited outside the organisation's own systems.
  3. Credentialed scanning is equivalent to a penetration test and needs the same approvals.
  4. Credentialed scanning removes the need for the scanner to hold a vulnerability database.
Show the answer

Answer: A. Some network-based scanners hold administrator credentials on the hosts and extract vulnerability information using them.

SP 800-115 notes some network-based scanners have administrator-level credentials on individual hosts and can extract vulnerability information from those hosts using them.

Source: NIST SP 800-115 (NIST) — SP 800-115 > 4.3 Vulnerability Scanning

Challenge yourself on this topic → Study as cards