A SOC engineer must determine whether servers have drifted from an approved CIS hardening benchmark, not whether they contain unpatched software. Which scanning method should be implemented?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: if you want to know whether a server is wearing the uniform, you check the settings, not just the patch level. An authenticated vulnerability scan hunts for CVEs, but configuration scanning compares live settings to your benchmark. That’s how you spot drift.
Full Explanation
Configuration scanning evaluates current system state against a defined benchmark, such as CIS controls or an internal hardening standard. It checks settings, permissions, services, and other configuration items, so it is the right method when the question is whether a system has drifted from an approved baseline. An authenticated vulnerability scan uses credentials to identify missing patches and software flaws; it may reveal known CVEs, but it does not primarily measure whether each required setting matches a benchmark. A credentialed software inventory scan collects installed applications, versions, and related metadata; that supports asset and patch management, yet it does not compare the full configuration posture to a hardening standard. A network port and service scan discovers listening ports and exposed services from the network perspective; it can identify unnecessary services, but it cannot validate many local settings, file permissions, or policy values needed for benchmark compliance. Exam caveat: CompTIA often distinguishes vulnerability scanning for software flaws from configuration or compliance scanning for baseline conformity, even when both may use credentials. Operational check: run a configuration scan against the approved benchmark and review the failed controls that represent drift, such as disabled logging, weak permissions, or noncompliant service settings.