An enterprise SOC needs to determine what internet-facing services and externally reachable weaknesses an attacker could discover without valid credentials. Which vulnerability scanning method should be implemented?
Select an answer to reveal the explanation.
Short Explanation
Think of it like knocking on the front door: if you want to know what an outsider sees, you scan from outside without credentials. An unauthenticated external scan shows exposed services and reachable flaws exactly as an attacker would. Don't let internal access or credentials blur the picture.
Full Explanation
The mechanism is to choose a scanning method whose location and credential state match the adversary viewpoint being tested. If the goal is to determine what an external attacker can discover before obtaining valid access, the scan should be unauthenticated and external, because it reveals internet-facing services, exposed ports, banners, weak TLS, and externally reachable flaws without privileged data. This supports attack-surface reduction by showing what is reachable from the public internet. An authenticated internal scan is useful for configuration assessment, patch verification, and host-level issues, but it represents an insider or post-compromise perspective rather than an outside adversary. An unauthenticated internal scan can identify lateral reachability and unprotected internal services, yet it assumes access inside the perimeter and cannot measure what is exposed across the boundary. An authenticated external scan can validate internet-facing systems with credentials, but credentials alter visibility and may expose content an unprivileged attacker could not reach. Exam caveat: align scan scope, location, and authentication with the specific risk question. Operational check: launch the scan from a host outside the perimeter, ensure no credentials are supplied, and reconcile discovered services against the approved internet-facing asset list.