CySA+ v4 · Objective 2.1

Planning vulnerability assessments

Design an assessment that answers a defined security question while respecting service availability. Select complementary scanning methods and make coverage gaps visible.

What you will be able to do

  • Build an assessment scope from asset ownership, sensitivity, exposure, and service dependencies.
  • Choose internal, external, agent-based, and agentless perspectives for a stated assessment goal.
  • Explain when credentialed, non-credentialed, active, passive, discovery, and baseline checks provide useful evidence.
  • Define operating limits, success criteria, and follow-up actions for an incomplete scan.

Learn the concepts

  1. Lesson 1

    Start with a question, an inventory, and an operating plan

    A scan is an evidence collection activity. Its value depends on knowing what should be assessed, what the assessment can observe, and which operational limits it must respect.

    Open lesson →
  2. Lesson 2

    Choose methods that reveal different parts of the system

    Scanning choices are independent dimensions. A useful plan combines perspectives and collection methods instead of expecting one tool configuration to answer every security question.

    Open lesson →

Apply your judgement · Synthetic scenario

The clean report with missing systems

In a fictional transport training centre, a scanner reports no high findings after a weekend assessment. The operations lead wants to announce that every training system has been checked.

Expected inventory
60 classroom desktops, 12 roaming instructor laptops, 8 simulator controllers.
Scanner summary
64 responding targets; credentialed checks succeeded on 44; 20 authentication failures.
Network position
Scanner located in classroom segment; simulator segment denies its assessment traffic.
Operating constraint
Controller vendor requires a supervised maintenance window; instructor laptops often disconnect on weekends.

Your task

  1. Identify why the report cannot demonstrate full coverage.
  2. Propose an assessment approach for each asset group.
  3. Write a completion statement and the next verification step.
Compare your response

The inventory contains 80 expected systems, but only 64 responded and only 44 received successful credentialed checks. The 20 authentication failures reduce depth. Identify which inventory records match those results before calculating coverage by device group; the current totals do not establish that the controllers or laptops were assessed.

Repair and test authorised credentials for the desktops. Use managed agents or agreed connected periods for instructor laptops, with freshness checks. Keep simulator segmentation intact and work with the owner on passive or configuration evidence followed by a supervised assessment from an approved location. Do not apply one broad scan profile to all three populations.

Report the assessment as partial, with no high findings in the successfully completed checks. Assign owners and dates to missing targets and authentication failures. Verify the revised plan against all 80 inventory entries, retaining explicit exclusions and remaining uncertainty before making a broader assurance statement.

Put it into practice

Use these labs alongside this module.

Check your understanding

Choose the best response to each scenario, then check your reasoning. These are course practice questions.

1. A scanner finds no hosts in an authorised server segment, but the asset inventory lists six active systems. What should the analyst do first?
2. Roaming laptops rarely connect during the scheduled overnight scan. Which change best improves host-level coverage?
3. A configuration baseline scan identifies a disabled setting that an application owner says is required for compatibility. What is the best next step?

0 of 3 answered

Source reading: supplied book, chapters 5, 6. Lessons, scenarios, and questions are original CyberCorps course material.