exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 190 discussion

Actual exam question from CompTIA's SY0-501
Question #: 190
Topic #: 1
[All SY0-501 Questions]

A technician has installed new vulnerability scanner software on a server that is joined to the company domain. The vulnerability scanner is able to provide visibility over the patch posture of all company's clients.
Which of the following is being used?

  • A. Gray box vulnerability testing
  • B. Passive scan
  • C. Credentialed scan
  • D. Bypassing security controls
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AntonioTech
4 years ago
The answer must be C as the question states that the server "joined the company domain."
upvoted 1 times
...
CSSJ
4 years, 6 months ago
Its C. Because there is no such thing as "Gray box vulnerability testing" its Gray box penetration testing. And also no "vulnerability testing" only vulnerability scan. Remember its vulnerability scan (scans is doing only basic things)vs penetration testing (testing is going deeper not only scanning) Hope makes sense
upvoted 3 times
...
Hanzero
4 years, 7 months ago
It is C
upvoted 2 times
...
Don_H
4 years, 9 months ago
there are many attributes to the question that points to a credential scan. Domain, visibility over entire company clients. Elimination process, option B&D are out. A is not as this is not pertaining to testing. the Answer is C - credential scan.
upvoted 2 times
...
vaxakaw829
4 years, 9 months ago
Security administrators often run credentialed scans with the privileges of an administrator account. This allows the scan to check security issues at a much deeper level than a non- credentialed scan. Additionally, because the credentialed scan has easier access to internal workings of systems, it results in a lower impact on the tested systems, along with more accurate test results and fewer false positives. (Darril Gibson’s Get Certified Get Ahead p. 574)
upvoted 1 times
...
kdce
4 years, 10 months ago
C. Credentialed scan - key company domain.
upvoted 4 times
...
CyberKelev
4 years, 10 months ago
it's C : Credentialed scan "Vulnerability scanners can run as a credentialed scan using the credentials of an account, or as non-credentialed without any user credentials. Security administrators often run credentialed scans with the privileges of an administrator account. This allows the scan to check security issues at a much deeper level than a non- credentialed scan. Additionally, because the credentialed scan has easier access to internal workings of systems, it results in a lower impact on the tested systems, along with more accurate test results and fewer false positives" Gibson book. Patch posture of all clients of the company so it can only be credential
upvoted 1 times
...
MelvinJohn
5 years, 2 months ago
B. Passive scanners...can check the current software and patch versions on networked devices. https://smallbusiness.chron.com/difference-between-active-passive-vulnerability-scanners-34805.html
upvoted 4 times
Dante_Dan
4 years, 12 months ago
But the vulnerabilty scanner is in a computer that is in the company domain. I think that makes it a credentialed scan. Answer C
upvoted 6 times
FNavarro
4 years, 1 month ago
If it's already installed on the host then why would it need credentials
upvoted 1 times
...
...
...
MelvinJohn
5 years, 2 months ago
B. A passive scan can provide basic - but not detailed - information regarding the patches on each computer scanned. The question says "to provide visibility over the patch posture of all company's clients."
upvoted 4 times
...
GCubed
5 years, 3 months ago
The vulnerability scanner is able to provide visibility over the patch posture of "ALL" company's clients. I think by the use of "ALL" in the above statement, it is credentialed scan that can give such a result so although it was not mentioned that the technician used known credentials it is somehow implied by the result he/she got. Since grey box testing has limited knowledge of the details of the program is unlike to give "ALL" information on clients
upvoted 4 times
...
marskhan
5 years, 3 months ago
Can someone explain why is it C and not A?
upvoted 1 times
Dedutch
4 years, 1 month ago
Gray box implies there is some but not total knowledge of the network. Usually it would refer to the person performing the scan not a device To get all patching posture you would need a credentialed scan. You may get some patching info from an uncredentialed scan but you would need credentials to get a software list from the machines. No uncredentialed scan is going to determine what version of notepad++ I got ;)
upvoted 2 times
...
...
Ales
5 years, 6 months ago
I believe the correct answer is: A. Gray box vulnerability testing Gray box testing, also called gray box analysis, is a strategy for software debugging in which the tester has limited knowledge of the internal details of the program. A gray box is a device, program or system whose workings are partially understood. Credentialed scans are scans in which the scanning computer has an account on the computer being scanned that allows the scanner to do a more thorough check looking for problems that can not be seen from the network.
upvoted 3 times
ChiliTheChicken
5 years, 4 months ago
The Correct Answer is A https://comptiaexamtest.com/Security+SY0-401/tag/vulnerability-scanner/
upvoted 1 times
...
kaheri
4 years, 3 months ago
i belive white, black and gray box make reference to the knowledge a pentester, app or program has about the system, no the "privileges" they have to do the task
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago