A vulnerability scan of an internal switch management interface reports that vendor default administrator credentials are still enabled. The interface is reachable only from a restricted SOC VLAN. How should the analyst classify this finding?
Select an answer to reveal the explanation.
Short Explanation
Think of default admin creds like leaving the key in the door: it doesn't matter if the door is only in your hallway. You classify it as a high-risk credential-management failure, not a patch problem or a false positive. The scanner may not have logged in, but the finding still tells you the configuration is wrong.
Full Explanation
Default credentials on a management interface are a configuration and credential-management failure because the device is exposed with known, vendor-published secrets. The risk comes from predictable access, not from missing software updates; an analyst prioritizes it as high because successful use can give administrative control, bypass authentication, and persist across reboots. A limited internal network path does not reduce it to low risk, since lateral movement, misconfigured VLANs, or compromised hosts can make the management plane reachable. Treating the result as a false positive because the scanner did not authenticate is also wrong; unauthenticated checks can still identify credential hygiene defects, and authenticated scanning would strengthen evidence rather than negate it. A firmware patch is not the primary remediation for default credentials, although patching may be needed for unrelated software defects. Exam caveat: classify findings by the failure type and exposure, not only by scan confidence or network reachability. Operational check: verify the interface state, change or disable default accounts, enforce MFA where supported, and re-scan to confirm remediation.