Triage BoardGet the app

Concept · Scanning methods

Credentialed vs non-credentialed vulnerability scans

A credentialed scan logs in to the target and reads what is installed and how it is configured; a non-credentialed scan sees only what the host exposes on the network, the view an outside attacker has. Credentialed results go deeper and carry fewer false positives. Objective 2.1 of the CS0-004 exam lists the pair among the scan types you choose between in vulnerability scanning methods.

  • Exam code CS0-004
  • Tickets here 8

Inside view, outside view

The same host as each scan type sees it
PointCredentialedNon-credentialed
How it sees the host≠Logs in over SSH, SMB or WMI, or runs as an agent, and reads packages, patches, registry and config filesProbes open ports and reads what services answer
Missing patches≠Read from the installed-software inventoryInferred from version strings, when a service reveals one
False positives≠Fewer: it checks the file or package actually installedMore: it guesses from what services announce
Local weaknesses (permissions, local privilege escalation, insecure settings)≠VisibleMostly invisible
Whose view it gives≠An insider or an attacker with a footholdAn unauthenticated outsider
New risk it creates≠The scan account: a privileged login on many hostsFalse comfort from a clean but shallow report
Load and intrusivenessSet by the checks you enableSet by the checks you enable

Rows marked ≠ are where the two differ.

How the exam frames the choice

CySA+ scanning questions usually state a goal and ask for the scan type. If the goal is patch compliance or measuring hosts against a configuration baseline such as the Center for Internet Security (CIS) Benchmarks, which objective 2.1 names, you need the inside view, so the answer is credentialed. If the goal is to see what an attacker on the internet would find, the answer is a non-credentialed scan from outside.

Objective 2.1 lists four separate pairs: internal or external, agent or agentless, credentialed or non-credentialed, active or passive. Questions mix them on purpose. An agent runs on the host, so its view is credentialed by nature. An agentless scan can be either, depending on whether you give it an account. External and non-credentialed often go together, but you can run a non-credentialed scan from inside the network too.

When a credentialed and a non-credentialed scan of the same host disagree, the question is which view could actually see the evidence. That is the same skill as deciding between a false positive and a false negative, and the output-reading side of it lives in vulnerability assessment tools.

For the methodology behind all of this, NIST SP 800-115, the technical guide to security testing and assessment, is the standard reference (NIST CSRC, checked October 2026).

Credentialed does not mean intrusiveTrap

An option that calls a credentialed scan "more intrusive" or "riskier for production" mixes two axes. Logging in lets the scanner read more; it does not make it send more aggressive probes. Intrusiveness comes from the checks you enable, such as denial-of-service tests or brute-force plugins, and either scan type can run them or skip them.

A credentialed scan you can trust

  1. Create a dedicated scan account

    One account used only by the scanner, with the rights its checks need and no interactive logon where the platform allows it.

  2. Keep the secret in the scanner

    Store the credential in the scanner's vault or a secrets manager rather than in scripts or shared documents. Objective 1.1 names secrets management for this reason.

  3. Plan around the business

    Schedule around operations, performance and data sensitivity, the planning factors objective 2.1 lists, and plan for segmentation so the scanner can reach what it must.

  4. Reconcile against the asset inventory

    Compare scanned hosts with the inventory so missing or new machines stand out.

  5. Watch the account itself

    Rotate the credential and alert on any use outside scan windows. A scan account logging in at midnight from a workstation is an indicator in its own right.

Two scans, one host

Before you read any scan exhibit, work out whether the scanner logged in to the host.

Ticket 1 / 8

0 right

INC-001

What is the primary purpose of using authenticated scanning in a vulnerability assessment?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AAuthenticated scanning is not meant to evade an IDS; logging in is about visibility, not stealth.
  2. BThe scanner uses credentials to inspect configurations and patch levels, not to collect sensitive business data.
  3. CTesting whether user passwords are weak is password auditing, a separate job from an authenticated scan.
  4. DCorrect: Logging in lets the scanner read installed software, patch levels, and local settings, so it finds missing patches and misconfigurations an outside scan cannot see.

INC-002

Compare the unauthenticated network scan and authenticated agent scan results for the same host. Which finding accurately reflects the true risk posture based on authenticated visibility?

Exhibit

Scan TypeCVEServiceFinding Status
UnauthenticatedCVE-2023-XYZPort 445 (SMB)Vulnerable
AuthenticatedCVE-2023-XYZRegistry CheckService Disabled
UnauthenticatedCVE-2022-ABCPort 80 (HTTP)Vulnerable
AuthenticatedCVE-2022-ABCFile CheckVulnerable

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AThe authenticated registry check shows the vulnerable service is disabled, so CVE-2023-XYZ is not actively exploitable.
  2. BCorrect: The unauthenticated scan guessed from the open SMB port, but the authenticated check shows the affected service is disabled, so this result is a false positive.
  3. CBoth scans flag CVE-2022-ABC, and the authenticated file check confirms it, so it is a true positive.
  4. DThe unauthenticated scan was wrong about CVE-2023-XYZ, so it does not reflect the true risk better than the authenticated view.

INC-003

Review the vulnerability scan comparison. Which finding explicitly demonstrates an unauthenticated scan producing a false positive due to restricted internal configuration visibility?

Exhibit

Finding IDUnauthenticated Scan ResultAuthenticated Scan ResultReported Vulnerability
Vuln-01Detected (Banner Grabbing)Not Detected (Patch Confirmed)Apache Struts RCE
Vuln-02Detected (Open Port 443)Detected (TLS 1.0 Enabled)Weak TLS Cipher Suite
Vuln-03Not DetectedDetected (Registry Key Check)Missing SMB Security Patch
Vuln-04Detected (Header Check)Detected (Header Check)Deprecated HTTP Headers

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AVuln-03 was missed by the unauthenticated scan and found by the authenticated one, which makes it a false negative.
  2. BCorrect: The unauthenticated scan flagged Struts RCE from a version banner, but the authenticated scan confirmed the patch, so it is a false positive caused by limited visibility.
  3. CBoth scans detected the deprecated headers the same way, so the results agree.
  4. DThe authenticated scan confirmed TLS 1.0 is enabled, so the unauthenticated finding was accurate.

INC-004

A security analyst reviews outputs from credentialed and non-credentialed scans of the same hosts. Which finding requires immediate remediation priority?

Exhibit

HostServiceEvidenceCVSSScan Type
DC01SMBMissing KB50012348.1Credentialed
DC01SMBPort 445 open5.3Non-credentialed
WEB02HTTPOutdated Apache7.5Credentialed
WEB02HTTPBanner shows version6.2Non-credentialed

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AFindings differ in severity and confidence, so treating them as equal ignores prioritization.
  2. BAn open port 445 on a domain controller is expected and only shows exposure; it is lower confidence and lower severity than a confirmed missing patch.
  3. CCorrect: The credentialed scan confirms a missing patch (CVSS 8.1) on a domain controller, a high-value asset, so it comes first.
  4. DThe outdated Apache on WEB02 is confirmed but has a lower score on a less critical asset than the domain controller finding.

INC-005

An internal credentialed scan and an external non-credentialed scan produce conflicting results for the same host. The internal scan shows several high-severity vulnerabilities while the external scan reports none. Which explanation and verification step best accounts for the discrepancy?

Exhibit

HostScan TypeVulnerabilities FoundEvidenceConfidence
web01Internal credentialedCVE-20XX-1234 (CVSS 9.8)AuthenticatedHigh
web01External non-credentialedNoneNoneN/A

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ACalling the external scanner misconfigured skips the more likely explanation, filtering, and assumes without checking.
  2. BPatching everything without checks ignores verification and the reason the results differ.
  3. CCorrect: The internal scan logs in and sees installed software, while the external scan is likely blocked by a firewall or filtering, so a targeted external check confirms what is actually reachable from outside.
  4. DExternal non-credentialed results are the least detailed view, so treating them as final would hide confirmed vulnerabilities.

INC-006

A non-credentialed scan reports a critical RCE on a production controller. What is the safest next step?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: A non-credentialed RCE finding may be a false positive, so it should be confirmed with a credentialed check during a maintenance window before disrupting a production controller.
  2. BEscalating an unverified finding to management can trigger costly action on what may be a false positive.
  3. CIsolating a production controller on unconfirmed evidence can cause the very outage the response is trying to avoid.
  4. DPatching an unverified finding on a production controller without testing risks outages and may fix nothing.

INC-007

A cybersecurity analyst is employing a tool to evaluate application security. This tool can carry out authenticated scans to identify vulnerabilities and security issues from the perspective of an authenticated user. What type of tool is being utilized by the cybersecurity analyst?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AA firewall analyzer reviews firewall rule sets; it does not test applications as a logged-in user.
  2. BAn IDS watches traffic for attacks; it does not actively scan an application for vulnerabilities.
  3. CA port scanner finds open ports and services; it does not log into an application to test its behavior.
  4. DCorrect: Web application scanners such as Burp Suite, ZAP, or Nikto can log in and test pages and functions that only authenticated users can reach.

INC-008

Following a network infrastructure update, a vulnerability scanner suddenly generates a massive spike in false-positive findings across previously secure internal subnets. What is the most likely systemic root cause?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AAn IPS update does not change what the vulnerability scanner reports, and the findings are described as false positives instead of real exploits.
  2. BCorrect: If the scanner's service account can no longer log in, it falls back to remote guesses such as banners, which produce many false positives on hosts that were clean.
  3. CDisabling compliance checks would reduce findings and could not create a spike of false positives.
  4. DLowering severity thresholds changes how findings are ranked or filtered but leaves their accuracy untouched.

Shift tally

0 / 0

Choosing and running the scan

Can I skip a penetration test if I run credentialed scans?

No. A credentialed scan lists known weaknesses from the inside. A penetration test tries to exploit and chain them to show real impact. The exam treats them as different activities with different goals.

Should I make the scan account a domain administrator?

Only if no narrower role can run the checks you need. A domain-wide administrator used on every host is a prize for an attacker, so give the account the least privilege that still lets the scanner read patches and configuration.

Can I run a credentialed scan without installing agents?

Yes. An agentless scanner logs in over the network with the account you give it, using SSH on Linux or SMB and WMI on Windows. Agents are the other route: they suit laptops that are often off the corporate network, at the cost of deploying and maintaining software on every host. Objective 2.1 lists agent and agentless as their own pair.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.