Your SOC scans an on-prem subnet reliably, but remote contractors use laptops that connect intermittently through VPN and rarely appear in network scans. A manager asks for vulnerability coverage on those endpoints without adding new VPN access. Which scanning method should implement?
Select an answer to reveal the explanation.
Short Explanation
Think of these laptops like mailboxes on the road: if the mail carrier can't reach the address, you need a carrier already inside the mailbox. Agent-based scanning works because the endpoint reports out to the platform, so you get results even when inbound network reachability is flaky. Don't chase VPN windows or unauthenticated scans when the agent can do the job reliably.
Full Explanation
Agent-based vulnerability scanning places a lightweight collector on each managed endpoint, where it gathers inventory, configuration, patch, and vulnerability data locally and transmits results to a central platform. This model suits distributed or remote systems because it does not require the scanner to initiate inbound connections; the endpoint reports outbound, enabling credentialed-quality assessment despite intermittent reachability. Unauthenticated network scanning is insufficient because it observes only externally visible services and cannot validate internal patch state, registry settings, or application versions. Credentialed network scanning depends on the scanner reaching the target during a scan window, which is unreliable for laptops that connect intermittently and may be offline during scheduled assessments. Web application scanning inventories URLs and tests web interfaces, not host-level state, so adding a laptop to that inventory does not assess the operating system or installed software. Exam caveat: choose the method that matches reachability and assessment depth, not simply the most automated or credentialed option. Operational check: verify the endpoint agent is installed, reporting to the platform, and returning recent vulnerability results for a representative sample of remote hosts.