A SOC analyst is configuring credentialed vulnerability scans for Windows and Linux servers in a hybrid estate. The scanner must verify patch levels and software inventory, but the security team forbids administrative credentials for scanning. Which credential scope should be used?
Select an answer to reveal the explanation.
Short Explanation
Think of a scanner like a mail clerk: it needs to read the labels, not open the vault. You want a read-only inventory account that proves patch levels without handing over admin rights. That's least privilege doing its job.
Full Explanation
Credentialed vulnerability assessment works when the scanner can read the local system record instead of guessing from network banners. The scanner needs to see installed packages, update or hotfix status, and software inventory so patch gaps can be validated. A dedicated service account with read-only inventory access supplies that visibility while preventing changes to the host. This is the least-privilege answer because it grants only the ability to inspect evidence. A local administrator account on each host can collect data, but it also grants write and control rights, so a stolen scanner credential becomes a serious foothold. An unauthenticated account cannot confirm local package versions or patch status on most operating systems, which leaves the assessment incomplete and increases false positives. A domain administrator account is excessive because it extends privileged access across the directory and creates a much larger blast radius. Exam caveat: choose the smallest privilege that still gives authoritative local validation, not the privilege that simply maximizes coverage. Operational check: create the account with read access to package inventory and update metadata, then verify the scan reports expected installed software and patch state without administrative changes.