A SOC analyst must scan a sensitive production service that cannot tolerate performance degradation. Which scanning approach should be scheduled?
Select an answer to reveal the explanation.
Short Explanation
Think of scanning like vacuuming during a family meeting: useful, but noisy. You want active checks when the service is already down or isolated, not when users are hammering it. The trap is choosing the most convenient time for analysts instead of the safest time for production.
Full Explanation
Active credentialed scanning can reveal authenticated patch levels, weak configurations, and missing controls, but it can also generate load, trigger protective responses, or restart services. For a sensitive production service, the right implementation is to run that scan inside an approved maintenance window, where the service is already subject to change control and temporary alert suppression. Running active unauthenticated scans during peak business hours increases the chance of user-facing degradation and makes normal activity harder to baseline. Passive network traffic analysis during normal operations is useful for detecting exposure or anomalous behavior, but it does not reliably enumerate host vulnerabilities or authenticated configuration state. Running credentialed scans immediately after a change request skips the controlled validation and rollback context that a maintenance window provides. Exam caveat: CompTIA expects scan timing to be governed by operational impact and change management, not analyst convenience. Operational check: verify the scan appears in an approved change ticket, confirm maintenance mode or isolation, and suppress expected alerts during the window.