In a hybrid SOC, a credentialed vulnerability scan initially reports missing patches on IaaS workloads. After a maintenance window, the analyst prepares a remediation report for system owners. Which evidence most strengthens the report's credibility?
Select an answer to reveal the explanation.
Short Explanation
Think of a remediation report like proof of delivery: saying the patch was applied is not as good as a signed receipt. Credentialed scan evidence shows the patch is actually present, so your stakeholders can trust the closure. The trap is accepting admin notes or unauthenticated banners as proof.
Full Explanation
Authenticated scan evidence is valuable because credentialed scanning lets the scanner query local package inventory, file versions, registry keys, or OS patch metadata. In a remediation report, that evidence converts a claimed patch action into a verified control state, reducing false positives from outdated banners, cached data, or incomplete deployment. It also supports auditability, supports risk-based decisions, and helps system owners accept closure without rework. Unauthenticated scan output is weaker because it infers vulnerability from exposed service banners or protocol responses; a missing banner does not prove the patch is installed, and a patched service may still expose misleading version strings. Ticket notes from an administrator are useful for workflow context but are self-reported and can miss partial deployment, reboot requirements, or failed installers. A generic claim that the scanner database is current describes tool hygiene, not host-level patch status, so it does not demonstrate that the affected systems were remediated. Exam caveat: choose the answer that provides direct, verified evidence of the patched condition rather than process documentation or indirect indicators. Operational check: rerun an authenticated scan or EDR inventory query after patching and attach the post-change package/version record to the closure ticket.