Objective 2.1 is a given a scenario objective (CS0-004 objectives, version 2.0, checked October 2026), so most items describe a real constraint and test whether your plan respects it. The planning considerations go in this order:
Scheduling and operations
A scan window has to fit around backups, batch jobs, change freezes and the people who will take the calls if something slows down. When the stem mentions a business calendar, the schedule is part of the answer.
Performance and sensitivity levels
Scanners use bandwidth on the wire and CPU on the target. You trade speed for stability with fewer hosts in parallel, lower rate limits and smaller check sets. Sensitivity levels decide how intrusive the checks are, from safe checks that only read banners to tests that can knock over a fragile service. Older appliances, printers and operational technology get the gentlest profile.
Segmentation and regulatory requirements
A firewall between scanner and target changes what the scanner sees, so a segmented network needs a scanner or agents inside each zone. Regulation sets some of the rules for you. PCI DSS requires external scans of the cardholder data environment by an Approved Scanning Vendor (PCI DSS v4.0.1 requirement 11.3, checked October 2026), on top of the internal scans your own team runs.
Asset inventory
Every one of these choices assumes you know what you own. An inventory records each asset's owner, its exposure and how critical it is, and those three fields drive the scan type, the window and the profile. Cloud workloads and containers come and go between scans, which is why discovery runs on a schedule of its own.