An analyst compares an external unauthenticated scan with an internal credentialed scan and sees different vulnerability counts. Management asks which results are more trustworthy for patching decisions. What should be communicated?
Select an answer to reveal the explanation.
Short Explanation
Think of an unauthenticated scan like peeking through the fence: you see what the yard exposes, but not what is inside the toolbox. A credentialed scan opens the cabinet and checks the labels, so patch-level confidence goes way up. When you report scan differences, spell out which mode you used so nobody treats a fence guess as a full inventory.
Full Explanation
Unauthenticated scans observe targets from outside the host, inferring issues from ports, banners, and external responses. Credentialed scans query the OS, package managers, and installed software inventory, increasing confidence in patch-level findings. Reporting should distinguish exposure from confidence: unauthenticated data can show reachability, but local package state is better evidence for missing patches. The view that unauthenticated scans are more trustworthy because credentials create noise is wrong; credentials improve visibility while requiring scope control. The claim that credentialed scans only confirm externally visible weaknesses reverses the concept, since they reveal host configuration and software state invisible from outside. The assertion that unauthenticated scans are more reliable for installed software versions is also incorrect, because banner or service fingerprinting is weaker than local package data. Exam caveat: when comparing scan types, separate coverage from confidence, and note authentication status in the report. Operational check: review failed logins and scan scope, then reconcile high-risk unauthenticated findings against credentialed results before setting remediation deadlines.