Which of the following activities should be performed first to compile a list of vulnerabilities in an environment?
Choose an answer
Tap an option to check your answer.
Correct answer: Automated scanning.
Why this is the answer
Automated scanning is the most efficient initial step for compiling a list of vulnerabilities. It uses tools to quickly identify common misconfigurations, missing patches, and known security flaws across a large number of systems. While not as deep as other methods, it provides a broad baseline assessment. Penetration testing (and adversarial emulation, a type of advanced penetration testing) is a more in-depth, manual process that simulates real-world attacks, typically performed after initial scans to validate findings or uncover complex vulnerabilities. Threat hunting is a proactive search for undetected threats, not primarily for compiling a vulnerability list. Log aggregation is for collecting and analyzing security event data, which can help detect incidents but isn't the primary method for initial vulnerability identification.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed