CompTIA CySA+ (CS0-003) — Question 453

A security administrator is tasked with modifying the vulnerability scan process to reduce the network traffic but maintain thorough checks. Which of the following scanning approaches should be implemented?

Answer options

Correct answer: D

Explanation

Agent-based scans reduce network traffic because the agents installed on devices perform the scanning locally and only send necessary information back to the central system. In contrast, credentialed scans (A) still require network communication, individual scans (B) can generate more traffic as they scan each device separately, and security baseline scans (C) do not focus on minimizing network load.