A vulnerability analyst needs to confirm which TCP and UDP ports on a database server are reachable from the analyst's scanning subnet and whether services respond to probes. Which scanning method should be used?
Select an answer to reveal the explanation.
Short Explanation
Think of it like knocking on doors: active service scanning asks each port, 'Are you home?' and records which ones answer. Passive scans just listen, so you’ll miss ports that only reveal themselves when probed. If your goal is reachable and responsive network services, you want the scan that actually pokes them.
Full Explanation
Active service and port scanning is appropriate when the goal is to determine which network ports are reachable from a source and whether listening services respond. The scanner sends TCP SYN, connect, or UDP probes, then records open, closed, filtered, or unresponsive states and may fingerprint services. This unauthenticated network assessment measures exposure from the scanner’s vantage point rather than relying on host configuration data. Passive vulnerability scanning is unsuitable because it observes traffic or logs without targeted probes, so it cannot reliably discover closed or filtered ports or confirm responsiveness. Authenticated configuration scanning is wrong because it depends on credentials to inspect patch levels, settings, or inventories; it may report installed services but does not prove network reachability. Agent-based endpoint scanning is inappropriate because it relies on an installed agent to report endpoint state, which can reveal local listeners but not external port reachability from the scanning subnet. Exam caveat: choose the method that directly measures network exposure, not the method with the richest host inventory. Operational check: run a targeted active scan from the approved subnet, then compare results with firewall policy and service baselines.