- Home
- All questions
- Question 388
CISSP study material · question 388 of 500
A scanning programme produces shallow results and the team is considering credentialed scanning. What does SP 800-115 say about that approach?
Show the answer
Answer: A. Some network-based scanners hold administrator credentials on the hosts and extract vulnerability information using them.
SP 800-115 notes some network-based scanners have administrator-level credentials on individual hosts and can extract vulnerability information from those hosts using them.
Source: NIST SP 800-115 (NIST) — SP 800-115 > 4.3 Vulnerability Scanning