An analyst compares two scans of the same Windows server. The authenticated scan lists dozens of missing patches and vulnerable applications, while the unauthenticated scan only reports exposed RDP and SMB. Which conclusion is best supported by the scan output?
Select an answer to reveal the explanation.
Short Explanation
Think of an unauthenticated scan like peeking through the front window. It only sees what the service shows from outside, so missing local patch data isn't proof of no exposure. You should treat the authenticated result as the fuller view and verify what's actually listening.
Full Explanation
An authenticated scan uses valid credentials to query the operating system, package inventory, registry, and installed applications, so it can detect local missing patches and vulnerable software that are not visible from the network. An unauthenticated scan only observes externally exposed services, banners, and version clues, so its narrower output usually means the scanner lacked local visibility rather than proving no risk exists. Analysts should confirm the authenticated scan actually succeeded, then separate externally exposed findings from internal remediation items. Treating the gap as false positives from local package metadata is weak because local metadata often corroborates missing patches and software inventory; false positives require a specific scanner defect, stale cache, or parsing error. Concluding the host is compromised because patches are missing confuses vulnerability with compromise, since missing patches create risk but do not show execution, persistence, or malicious indicators. Saying authenticated findings are invalid because credentials cannot be used contradicts the detailed local results; if credentials failed, the scan should show authentication failure or remain limited to remote checks. Exam caveat: the exam wants you to interpret scan coverage, not assume a finding is real or fake from one scan type. Operational check: rerun the scan with verified credentials and confirm the report shows successful OS and package enumeration before prioritizing remediation.