Security Scan FAQ

Frequently Asked Questions (FAQs)

Table of Contents

 

Questions & Answers

What Types Of Vulnerability Scans Does IT Security Offer, And How Can I Request A Scan?

The OSU Information Security Services group offers vulnerability scanning for your servers, workstations, or websites. The results of vulnerability scans can be used to proactively locate, identity, and assess vulnerabilities. Ideally, the results allow departments to prioritize and re-mediate the systems before they are targeted and exploited by attackers. Vulnerability scans help protect University data and can mitigate the risk of unauthorized access, theft, or malicious destruction.

 

 For more information regarding Vulnerability Scans, please visit: https://it.okstate.edu/services/vulnerability-scans/index.html


What is the difference between an Agent and Network Scan?

  • An Agent Scan is a vulnerability scan run by the Nessus Agent already installed on the system. The scan is run to see what local/system-side vulnerabilities are on the host. 
  • A Network Scan is a vulnerability scan run over the network on any system connected to the network. The scan is run to see what network-facing vulnerabilities are on the host. 

What is the difference between a Credentialed Scan or Non-Credentialed Scan? 

  • A Credentialed Scan is a web scan that requires credentials to log into the website in order to view content on the site. 
  • A Non-Credentialed Scan is a web scan that does not require any login to view content on the site.