A hospital SOC must inventory medical imaging hosts in a restricted VLAN. Active scanning is prohibited because it could interrupt imaging sessions, and the hosts rarely respond to ICMP. The team has NetFlow, DHCP logs, and EDR telemetry. Which discovery method should the analyst use to build an accurate asset inventory?
Select an answer to reveal the explanation.
Short Explanation
Think of it like counting cars by watching the driveway and checking the garage log, not by honking at them. You don't need to knock on every door when NetFlow, DHCP, and EDR already tell you who's around. The trap is that credentialed or port scans would answer a different question.
Full Explanation
Passive discovery derives inventory from data already produced by the environment. NetFlow or IPFIX shows conversations and host roles, DHCP logs reveal addresses and leases, and EDR telemetry confirms installed software and endpoint identity. Correlating these sources lets an analyst infer assets without sending new probes, which is essential when scanning could disrupt clinical systems or when hosts ignore ICMP. Active scanning methods are inappropriate here because they intentionally generate traffic against targets. Credentialed scanning requires valid accounts and access to systems that may be locked down or nonstandard, and it still performs active enumeration. Agentless active scanning from a management subnet still sends probes into the restricted VLAN and may violate change-control restrictions. Port scanning every address is even more disruptive and noisy, producing false positives and possible service interruption. Exam caveat: choose passive telemetry when the objective is inventory under operational constraints, not when the task requires confirmed software versions from authenticated queries. Operational check: export one week of NetFlow, DHCP, and EDR asset events, normalize on hostname, MAC, IP, and process path, then reconcile mismatches before declaring the inventory complete.