A SOC receives a report that a production SQL database may allow excessive application privileges, anonymous authentication, and exposed schema paths. The analyst must assess the database configuration rather than only host patch status. Which scanning method should be implemented?
Select an answer to reveal the explanation.
Short Explanation
Think of it like checking the locks and keys inside a vault — it's not just the front door. If the risk is database privileges, auth settings, or schema paths, you need a credentialed database scan — not an OS patch scan or a web scan. The trap is picking a scan that sounds close but doesn't inspect the database objects themselves.
Full Explanation
Mechanism: A credentialed database scan is selected when the suspected exposure lies inside the database layer: authentication modes, account roles, schema permissions, exposed stored procedures, and object-level access paths. The scanner uses an account with enough privileges to enumerate metadata and configuration settings, allowing findings such as public roles, excessive grants, disabled auditing, or anonymous access to be detected and correlated to risk. Why wrong: An unauthenticated external port scan can prove reachability and open ports, but it cannot inspect internal database permissions or authentication settings. A credentialed operating-system patch scan checks host-level packages, registry keys, and service updates; it may miss database-specific configuration and privilege issues. A dynamic web application scan targets HTTP interfaces, input validation, and session handling, not the database engine's own schema and role model. Exam caveat: choose the scan scope that matches the control plane being assessed, not merely the server hosting the service. Operational check: validate that the scan account has read-only access to system catalogs and configuration views, then review findings for excessive grants, anonymous authentication, and exposed data paths.