Study. uk . com
  1. Home
  2. All questions
  3. Question 580

CompTIA Security+ study material · question 580 of 611

What does port and service identification contribute to a vulnerability assessment?

  1. It reveals what is listening and which software answers, so relevant checks can be selected
  2. It establishes the asset's business criticality
  3. It produces the CVSS environmental score
  4. It confirms the finding can be exploited
Show the answer

Answer: A. It reveals what is listening and which software answers, so relevant checks can be selected

Without knowing what software is present, the scanner cannot decide which vulnerability checks are even applicable.

Source: NIST SP 800-115 (NIST) — SP 800-115 § 4.2 Network Port and Service Identification

Challenge yourself on this topic → Study as cards