Skip to content
ScopefileGet the app

Technique fileVulnerability analysis

Vulnerability assessment vs penetration test

A vulnerability assessment finds and ranks weaknesses across many systems; a penetration test tries to exploit chosen weaknesses, inside an agreed scope, to show how far an attacker could get.

Exam
312-50
Domain
3 · System hacking
Targets
8

Breadth versus proof

One way to hold the pair apart: an assessment asks what is weak, a pen test asks how far someone could get. The assessment is wide and non-intrusive; the pen test is narrow and goes deep on a few targets. Both sit in the Vulnerability Analysis module.

Both need written authorization and a defined scope. The difference is depth, not permission. The documents behind that authorization are listed in ethical hacking vs penetration testing.

Both feed the same six-step vulnerability-management life cycle: pre-assessment, vulnerability assessment, risk assessment, remediation, verification and monitoring, each step explained in the vulnerability analysis file.

Side by side

Two engagement types, trait by trait
TraitVulnerability assessmentPenetration test
Core question (differs)What weaknesses exist?How far can an attacker get?
Coverage (differs)Broad, many hostsNarrow, chosen targets
Exploitation (differs)NoneWithin the agreed scope
Main output (differs)Findings listNarrative report
Written authorizationRequiredRequired
Cadence (differs)Repeated on a schedulePoint in time

Tinted rows marked ≠: the two differ.

Assessment types by vantage point

Active vs passive
Active sends probes to systems; passive watches traffic and configuration without touching hosts.
External vs internal
External looks from the internet at what is exposed; internal looks from inside the network.
Host-based vs network-based
Host-based examines one system's software and settings; network-based examines what the network reveals about many systems.
Application and database
Focus on one class of target, such as web applications or database servers, with checks specific to it.
Wireless
Covers access points, client configuration and the encryption in use on Wi-Fi networks.

Assessment or pen test?

Decide what each engagement is meant to produce before choosing.

Answered 0/8Hits 0

T-01

Which type of assessment can detect software vulnerabilities, identify unsupported operating system versions, unused services that should be disabled, and configuration weaknesses that may pose security risks?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA compliance audit checks controls against a specific standard or regulation, not a broad technical sweep for flaws.
  2. BPenetration testing goes beyond listing weaknesses to actively exploit them, so a broad inventory of flaws is not its main goal.
  3. CRisk assessment weighs likelihood and business impact of threats, using vulnerability data as an input rather than producing it.
  4. DCorrect: a vulnerability assessment systematically identifies missing patches, unsupported systems, needless services and misconfigurations without exploiting them.
T-02

What is the primary purpose of a penetration test?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: a penetration test emulates real attackers under authorization to find exploitable weaknesses and demonstrate their impact.
  2. BRecovering data after a breach is incident response and disaster recovery work, not penetration testing.
  3. CChecking whether staff follow policy is a compliance or audit activity, although social engineering tests may touch on it.
  4. DMeasuring performance under heavy load is stress or load testing, which is a quality assurance activity.
T-03

A penetration testing proposal includes credentialed scanning with domain administrator accounts to enumerate patches and local configurations across Windows servers. The client questions whether this violates the intended non-intrusive assessment boundary. What is the correct clarification?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACredentials give read access for inventory; intrusiveness depends on whether vulnerabilities are exploited, not on whether administrative rights are used.
  2. BExploitation means abusing a flaw to gain unintended access, whereas credentialed scanning uses legitimately granted access to read settings.
  3. CCorrect: credentialed scans log in to read patch levels and configurations, which deepens visibility without exploiting any weakness.
  4. DAuthentication alone does not cross a non-intrusive boundary; authenticated scans are standard practice in vulnerability assessment programs.
T-04

An unauthenticated scan of a Windows server yields zero critical findings. A subsequent authenticated scan of the identical server reveals multiple missing high-severity operating system patches. What is the most likely reason for this discrepancy?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA newly released exploit would not make older missing patches appear, since the authenticated scan reads what is installed on the host.
  2. BUnauthenticated scans more often miss local issues than invent them, and the stem shows missing findings rather than false positives.
  3. CCorrect: authenticated scans log in to inspect installed software, registry and file versions, revealing missing patches that remote probing cannot see.
  4. DThe scans ran against an identical server, and the missing operating system patches point to scan visibility rather than new software.
T-05

A vulnerability scanner identifies a critical remote code execution vulnerability on a production database server. Which action best aligns with safe assessment practices to verify this finding?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARunning an exploit module to gain a shell crosses from assessment into exploitation and risks crashing a production database without explicit authorization.
  2. BAn unauthenticated intrusive scan adds more risk and noise while yielding weaker evidence than examining the system's configuration directly.
  3. CA denial-of-service payload deliberately disrupts the service, which violates safe assessment practice on a production server and proves nothing about the flaw.
  4. DCorrect: checking versions, configuration and logs confirms or rules out the finding passively, which is how assessments verify results without risking production.
T-06

An enterprise network has internet-facing web servers in a DMZ, internal application servers on a corporate LAN, and workstations distributed across branch offices. The security team must assess both external attack surface and internal patch compliance. Which scanning strategy is MOST appropriate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: external unauthenticated scans show what an attacker on the internet sees, while credentialed internal scans verify patch compliance in depth.
  2. BPenetration testing the DMZ has value, but questionnaires provide no technical verification of internal patch levels.
  3. CCredentialed scans everywhere give depth but do not reveal the external attacker's view of the internet-facing DMZ hosts.
  4. DEndpoint detection and response complements scanning but does not replace vulnerability assessment of server patch levels and exposure.
T-07

A scan flags an outdated web server. The client's board now asks for evidence that an outsider could actually use the flaw to reach customer data, and what that would mean for the business. Which engagement answers this request?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA credentialed assessment finds more weaknesses with better accuracy, but it still identifies and ranks them rather than proving they can be exploited.
  2. BRescanning with newer signatures only refreshes the list of findings; it never demonstrates that an attacker could reach customer data.
  3. CA policy gap analysis compares controls with a framework on paper; it does not test whether a specific flaw is exploitable in practice.
  4. DCorrect: a scoped penetration test attempts exploitation under rules of engagement and shows the real attack path and business impact the board asked for.
T-08

A merchant's compliance program requires quarterly scans that list every known weakness on internet-facing systems, ranked by risk, with no exploitation attempted against production. Which engagement and deliverable fit this requirement?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA penetration test exploits weaknesses to show attack paths, which the requirement forbids against production and goes beyond a broad severity-ranked inventory.
  2. BCorrect: a vulnerability assessment identifies and ranks known weaknesses by severity without exploiting them, which is exactly what a recurring compliance scan needs.
  3. CA red team exercise tests detection and response against chosen objectives; it is not a complete, severity-rated listing of every weakness.
  4. DProof-of-access evidence comes from actually exploiting hosts, so this deliverable contradicts the rule that nothing in production may be exploited.

Scans, red teams and OT

Is a vulnerability scan the same as a vulnerability assessment?

No. The scan is one input. The assessment adds validation, analysis and prioritization on top of the scanner output.

Where does a red team fit?

Beyond both. A red team pursues a specific objective over weeks or months and tests detection and response as much as the systems themselves.

Does the comparison change for industrial systems?

Yes. In operational technology, availability and safety come first, so intrusive testing on live control systems is handled with far more caution; the IT vs OT security page explains why.

Sources