QuestionQ57

Vulnerability Management

A vulnerability scanner shows discrepancies between the number of Internet Protocol (IP) addresses across the sites being scanned and the number of systems reporting into the patching system. Which of the following actions will resolve this issue?

  • A Enable verbose logging in the scanner and check for failures.
  • B Rebuild the vulnerability report selection criteria to account for all sites.
  • C Request the infrastructure team rerun patching deployments.
  • D Conduct a comprehensive asset inventory with the infrastructure team.
Explanation

The mismatch between scanned IP addresses and systems reporting into the patch management system points to an incomplete or inaccurate asset inventory — some devices may not be enrolled in patching, may be rogue/unauthorized, or may be missing from the CMDB. Performing a comprehensive asset inventory together with the infrastructure team identifies all systems across the sites, reconciles scanner findings with patch management records, and ensures both tools reference the same authoritative list of assets, which directly resolves the root cause of the discrepancy rather than just adjusting scan reporting or reissuing patches.

Community Discussion

No comments yet. Be the first to start the discussion!