- Home
- All questions
- Question 134
CompTIA Security+ study material · question 134 of 611
A patch compliance report built from unauthenticated scans shows far fewer missing patches than the software inventory suggests. What is the likely cause?
Show the answer
Answer: C. An unauthenticated scan cannot see installed package versions
Only a credentialed scan logs in and reads installed versions and configuration, which is what patch compliance needs.
Source: NIST SP 800-115 (NIST) — SP 800-115 § 4.3 Vulnerability Scanning