What is the primary purpose of using authenticated scanning in a vulnerability assessment?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
- AAuthenticated scanning is not meant to evade an IDS; logging in is about visibility, not stealth.
- BThe scanner uses credentials to inspect configurations and patch levels, not to collect sensitive business data.
- CTesting whether user passwords are weak is password auditing, a separate job from an authenticated scan.
- DCorrect: Logging in lets the scanner read installed software, patch levels, and local settings, so it finds missing patches and misconfigurations an outside scan cannot see.