exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 87 discussion

Actual exam question from CompTIA's SY0-501
Question #: 87
Topic #: 1
[All SY0-501 Questions]

Which of the following would MOST likely appear in an uncredentialed vulnerability scan?

  • A. Self-signed certificates
  • B. Missing patches
  • C. Auditing parameters
  • D. Inactive local accounts
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
emilykaldwin
Highly Voted 6 years ago
Correct answer should be B, see https://subscription.packtpub.com/book/networking_and_servers/9781789348019/8/ch08lvl1sec91/credentialed-versus-non-credentialed-scans
upvoted 19 times
Drui
4 years, 10 months ago
Ian Neil guide says: Non-credentialed: A non-credentialed scan will monitor the network and see any vulnerabilities that an attacker would easily find; we should fix the vulnerabilities found with a non-credentialed scan first, as this is what the hacker will see when they enter your network. For example, an administrator runs a non-credentialed scan on the network and finds that there are three missing patches. The scan does not provide many details on these missing patches. The administrator installs the missing patches to keep the systems up to date as they can only operate on the information produced for them. •Credentialed scan: A credentialed scan is a much safer version of the vulnerability scanner. It provides more detailed information than a non-credentialed scan. You can also set up the auditing of files and user permissions. Exam tip: A credentialed scan can produce more information and can audit the network. A non-credentialed scan is primitive and can only find missing patches or updates.
upvoted 9 times
...
frededel
5 years, 4 months ago
I guess banner grabbing would show older versions of services running on a non-credentialed scan.
upvoted 3 times
...
...
toenose
Highly Voted 4 years, 6 months ago
Comptia on their end. Hahahah its so funny to watch people stress out.
upvoted 8 times
...
StickyMac231
Most Recent 4 years, 1 month ago
you must know what is that scan can do. i will tell you what exactly why they choose D. because inactive local account can be compromise by attackers. And i did some research and that is why choice D is related to this explanation: Non-credentialed scans enumerate ports, protocols, and services that are exposed on a host and identifies vulnerabilities and misconfigurations that could allow an attacker to compromise your network.
upvoted 1 times
troxel
4 years ago
Except you can't find inactive local accounts via non-credential scan.
upvoted 2 times
...
...
aSabz
4 years, 5 months ago
Cons: Misses client-side vulnerabilities such as detailed patch information. https://docs.tenable.com/nessusagent/Content/TraditionalScansUncredentialed.htm
upvoted 1 times
...
Hanzero
4 years, 10 months ago
non-credentialed scans give an incomplete picture meaning missing patches so answer is B.
upvoted 3 times
...
Omario944
4 years, 10 months ago
A non-credentialed scan is also passive but can only identify missing patches
upvoted 2 times
...
trairi
4 years, 11 months ago
Plugin 10913 from Nessus is able to identify as disabled accounts in a scan without authentication. Correct answer is "D"
upvoted 1 times
...
trairi
4 years, 11 months ago
Plugin 10913 from Nessus is able to identify as disabled accounts in a scan without authentication. Correct answer is "D"
upvoted 1 times
dieglhix
4 years, 9 months ago
not in GCGA book, thus, B can only be correct.
upvoted 2 times
...
...
robopips
4 years, 11 months ago
Answer is B from this site: https://subscription.packtpub.com/book/cloud_and_networking/9781789348019/8/ch08lvl1sec91/credentialed-versus-non-credentialed-scans the answer to this question is so confusing!
upvoted 1 times
...
mlonz
4 years, 11 months ago
some say B and some say D, Pretty confusing.
upvoted 3 times
...
GJEF
5 years ago
The question says, "MOST LIKELY..." All the options could be part of the result but one of them would most likely be seen with a non-credential scan. Inactive users...
upvoted 2 times
...
jowen
5 years ago
It is B.
upvoted 1 times
...
callmethefuz
5 years ago
this has to be B because it isn't a credentialed scan. Banner grabbing allows for an attacker to determine the software patch running on a device and device type
upvoted 1 times
...
Nicker92
5 years, 1 month ago
To know if a system is patched you need to run a credential scan. A non-credential scan che find out a NTLM service with inactive accounts! Answer is D!
upvoted 2 times
DookyBoots
4 years, 8 months ago
Not true at all, that's why banner grabbing shows versions of software and Operating Systems, which do not require credentials. Do patches not change version numbers? I think this place has more people that do damage instead of helping. If you took the exam already, how many times did it take you to pass it?
upvoted 1 times
EliCash
4 years, 1 month ago
D, is arguably the best option for this question. No need to insult someone's intelligence because it differs from your opinion. B, is incorrect due to non-credentialed vulnerability scans "Misses client-side vulnerabilities such as detailed patch information." C, is incorrect, non-credentialed scans will not audit. Furthermore, Non-credentialed scan assess what normal users can see, regardless of privileges'. Finding self-signed certs require privilege (admin).
upvoted 1 times
troxel
4 years ago
You can determine a self-signed by looking at the CA and who it was issued by.
upvoted 1 times
...
...
...
...
virtualwalker
5 years, 2 months ago
There is no way uncredentialed scan can reveal inactive local accounts, correct answer should be B:
upvoted 2 times
...
ibernal01
5 years, 2 months ago
https://docs.tenable.com/nessusagent/Content/TraditionalScansUncredentialed.htm
upvoted 2 times
...
colamix
5 years, 2 months ago
I go with missing patches --> Non-credentialed: A non-credentialed scan will monitor the network and see any vulnerabilities that an attacker would easily find; we should fix the vulnerabilities found with a non-credentialed scan first, as this is what the hacker will see when they enter your network. For example, an administrator runs a non-credentialed scan on the network and finds that there are three missing patches. The scan does not provide many details on these missing patches. The administrator installs the missing patches to keep the systems up to date as they can only operate on the information produced for them.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...