Study. uk . com
  1. Home
  2. All questions
  3. Question 134

CompTIA Security+ study material · question 134 of 611

A patch compliance report built from unauthenticated scans shows far fewer missing patches than the software inventory suggests. What is the likely cause?

  1. Unauthenticated scans always report false positives
  2. The scanner was misconfigured for the wrong subnet
  3. An unauthenticated scan cannot see installed package versions
  4. The inventory includes decommissioned hosts
Show the answer

Answer: C. An unauthenticated scan cannot see installed package versions

Only a credentialed scan logs in and reads installed versions and configuration, which is what patch compliance needs.

Source: NIST SP 800-115 (NIST) — SP 800-115 § 4.3 Vulnerability Scanning

Challenge yourself on this topic → Study as cards