An analyst is performing a vulnerability scan against the web servers exposed to the internet without a system account. Which of the following is most likely being performed?
Choose an answer
Tap an option to check your answer.
Correct answer: Non-credentialed scan.
Why this is the answer
A non-credentialed scan is performed without providing login credentials (like a system account) to the target system. This type of scan simulates an external attacker's perspective, identifying vulnerabilities accessible without authentication. The question states the scan is against web servers "without a system account," directly matching the definition of a non-credentialed scan. Packet capture involves intercepting network traffic, not actively scanning for vulnerabilities. Privilege escalation is an attack technique to gain higher access, not a type of vulnerability scan. System enumeration is the process of gathering information about a system, which can be part of a scan but isn't the scan type itself. A passive scan analyzes network traffic or system configurations without actively interacting with the target, whereas a vulnerability scan actively probes for weaknesses.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed