An enterprise SOC supports an OT segment with legacy PLCs and environmental sensors used in a manufacturing line. Availability and safety are critical, and the scanner's active probes previously caused a controller to reboot. Management asks for vulnerability visibility without introducing additional disruption. Which vulnerability scanning method should the analyst implement first?
Select an answer to reveal the explanation.
Short Explanation
Think of OT like a hospital ICU: you can listen to the heartbeat, but don't poke the patient. Passive scanning lets you watch traffic and spot devices without sending probes that could crash a controller. You avoid the outage trap while still getting vulnerability intel.
Full Explanation
Passive vulnerability assessment observes existing traffic, flows, logs, or packet captures to fingerprint devices, protocols, and potential exposures without generating probes. In an OT or IoT segment, legacy controllers, sensors, and embedded devices often have fragile TCP/IP stacks, so active scanning can trigger resets, watchdog faults, or safety-system instability. A passive method lets the analyst inventory assets and infer vulnerabilities from observed behavior while preserving availability.
Authenticated active scanning is still an active method; credentials do not remove the risk of probes, session handling, or authentication traffic causing a device to hang. Maintenance windows may reduce business impact, but active probes can still interrupt control loops, safety interlocks, or production processes. Approval and timeout tuning do not make active scanning safe for legacy OT devices, and aggressive checks increase scan intensity, raising false positives and destabilizing low-power or nonstandard IoT devices.
Exam caveat: CompTIA expects analysts to choose the least disruptive scanning method when availability and safety dominate the risk profile. Operational check: confirm the scanner receives mirrored traffic from a span port or network tap and correlates observed fingerprints to OT/IoT vulnerability sources before issuing findings.