While performing an internal vulnerability assessment, you first execute a non-credentialed OpenVAS scan against a group of CentOS servers, then repeat the scan using valid SSH credentials. The initial run reports several missing kernel patches, but the credentialed scan lists none of them. Which statement best explains this discrepancy?
The non-credentialed scan's use of TCP connect probes inherently overestimates patch requirements on Unix systems, inflating the results.
The credentialed scan logs in via SSH and queries the system's package database, so it can confirm installed kernel versions and eliminate banner-based false positives.
The credentialed scan suppresses kernel-level findings by default to avoid destabilizing production servers.
A failed SSH key-exchange during the second scan caused the scanner to discard all vulnerability data for the targets, explaining the empty report.
Credentialed vulnerability scans log in to the target host and inspect local configuration data such as the RPM or DPKG package database, file hashes, and registry keys. Because they read definitive information directly from the system, they can accurately verify whether a patch is really absent or already installed. Non-credentialed scans must infer patch levels from banner grabbing and remote fingerprinting, which often produces false positives when banners are outdated or customized. The other options are incorrect: credentialed scans do not intentionally suppress kernel vulnerabilities, non-credentialed TCP probes do not systematically misreport Unix patch levels, and a failed SSH key exchange would have affected only the credentialed scan, not the non-credentialed one.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a credentialed scan?
Open an interactive chat with Bash
What is banner grabbing in vulnerability scanning?
Open an interactive chat with Bash
Why might kernel patch discrepancies appear in non-credentialed scans?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
System Hacking Phases and Attack Techniques
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .