Your SOC runs credentialed vulnerability scans nightly against hybrid servers. The scanner finds missing patches, weak ciphers, and exposed ports, but it does not stop the vulnerable systems from being attacked. In control-type terms, what role does this scanning primarily fulfill?
Select an answer to reveal the explanation.
Short Explanation
Think of a vulnerability scan like a smoke detector: it tells you there's a problem, but it doesn't put out the fire. You classify it as detective because it finds existing weaknesses after they're there. Don't let the word 'security' make you call it preventive; scanning doesn't stop the attack.
Full Explanation
Vulnerability scanning is primarily an assessment activity that supports detective controls: it observes the current configuration state, compares it to known baselines or CVE data, and produces evidence of weaknesses such as missing patches, weak ciphers, or exposed ports. It does not itself enforce policy, change system state, or reduce exposure until a separate remediation or blocking action occurs. A preventive control would stop an undesirable action before it happens, such as a firewall rule, application allowlisting, or a configuration-enforcing GPO, so treating scanning as preventive overstates its function. A corrective control acts after a problem is detected to restore a secure state, such as patching, re-imaging, or quarantining a host; scanning can trigger those actions but does not perform them. A compensating control provides alternative risk reduction when the primary control is impractical, such as network segmentation or WAF rules for an unpatchable system; the scanner only identifies the condition that may require compensation. Exam caveat: choose the control type based on whether the activity detects, prevents, corrects, or compensates, not on the tool category. Operational check: confirm that scan findings are routed to ticketing and remediation workflows with owner, due date, and verification scan.