Quarterly authenticated scanning of the county property-appraisal system reports missing OS and application patches. What is the primary security-assessment purpose of that activity?
Select an answer to reveal the explanation.
Short Explanation
Think of authenticated scans as a flashlight with a key—they see missing patches from the inside. The point is finding weaknesses so leaders can fix them, not rewriting policy, skipping baselines, or claiming risk is gone.
Full Explanation
Authenticated vulnerability assessment is a control-testing technique that discovers missing patches and related exposures using credentialed visibility. Results feed risk-based remediation rather than rewriting policy, substituting for baselines, or asserting that residual risk is zero. CISSP-level practice treats scan output as evidence for management action, not as a complete assurance program by itself.