A monthly vulnerability report shows that 31% of on-prem servers and 47% of cloud VMs were not scanned. Which report section should the analyst use to communicate this incomplete visibility as a risk to the vulnerability management program?
Select an answer to reveal the explanation.
Short Explanation
Think of a scan report like a map: if half the roads aren't surveyed, you can't say the territory is safe. The coverage summary is where you admit what wasn't scanned so leadership sees the blind spot, not just the findings. Don't bury that in the executive summary or fix list; make the missing visibility explicit.
Full Explanation
A coverage summary exists to state what was included in an assessment and what was not, so stakeholders can judge whether the findings represent the full environment. In a hybrid estate, unscanned on-prem systems and cloud workloads create unknown risk; documenting that gap prevents the report from implying that absence of findings equals absence of vulnerabilities. An executive summary condenses conclusions and priorities for leadership, but it is not the section that inventories scanned versus unscanned assets unless it summarizes the coverage statement. Remediation recommendations describe how to fix confirmed findings, and they can mislead when written as if all assets were evaluated. An asset criticality matrix ranks business value or exposure to guide prioritization, but it does not reveal whether an asset was actually assessed. Exam caveat: choose the section that communicates assessment boundaries and completeness, not the section that interprets risk or proposes fixes. Operational check: compare scanner target lists and cloud inventory exports, then update the coverage summary with counts of unscanned assets and the reason.