CySA+ v4 · Objective 2.1
Planning vulnerability assessments
Design an assessment that answers a defined security question while respecting service availability. Select complementary scanning methods and make coverage gaps visible.
What you will be able to do
- Build an assessment scope from asset ownership, sensitivity, exposure, and service dependencies.
- Choose internal, external, agent-based, and agentless perspectives for a stated assessment goal.
- Explain when credentialed, non-credentialed, active, passive, discovery, and baseline checks provide useful evidence.
- Define operating limits, success criteria, and follow-up actions for an incomplete scan.
Learn the concepts
- Lesson 1
Start with a question, an inventory, and an operating plan
A scan is an evidence collection activity. Its value depends on knowing what should be assessed, what the assessment can observe, and which operational limits it must respect.
Open lesson → - Lesson 2
Choose methods that reveal different parts of the system
Scanning choices are independent dimensions. A useful plan combines perspectives and collection methods instead of expecting one tool configuration to answer every security question.
Open lesson →
Apply your judgement · Synthetic scenario
The clean report with missing systems
In a fictional transport training centre, a scanner reports no high findings after a weekend assessment. The operations lead wants to announce that every training system has been checked.
- Expected inventory
- 60 classroom desktops, 12 roaming instructor laptops, 8 simulator controllers.
- Scanner summary
- 64 responding targets; credentialed checks succeeded on 44; 20 authentication failures.
- Network position
- Scanner located in classroom segment; simulator segment denies its assessment traffic.
- Operating constraint
- Controller vendor requires a supervised maintenance window; instructor laptops often disconnect on weekends.
Your task
- Identify why the report cannot demonstrate full coverage.
- Propose an assessment approach for each asset group.
- Write a completion statement and the next verification step.
Compare your response
The inventory contains 80 expected systems, but only 64 responded and only 44 received successful credentialed checks. The 20 authentication failures reduce depth. Identify which inventory records match those results before calculating coverage by device group; the current totals do not establish that the controllers or laptops were assessed.
Repair and test authorised credentials for the desktops. Use managed agents or agreed connected periods for instructor laptops, with freshness checks. Keep simulator segmentation intact and work with the owner on passive or configuration evidence followed by a supervised assessment from an approved location. Do not apply one broad scan profile to all three populations.
Report the assessment as partial, with no high findings in the successfully completed checks. Assign owners and dates to missing targets and authentication failures. Verify the revised plan against all 80 inventory entries, retaining explicit exclusions and remaining uncertainty before making a broader assurance statement.
Put it into practice
Use these labs alongside this module.
Check your understanding
Source reading: supplied book, chapters 5, 6. Lessons, scenarios, and questions are original CyberCorps course material.