skip to content

In Nessus Professional, what does a compliance scan with an audit file check that a vulnerability scan does not, and how do you customise one?

level: middleimportance: should knowfreq 17%

answer

  1. configuration, not missing patches
  2. Policy Compliance Auditing, Compliance tab
  3. each audit needs its own credentials
  4. variables like @NTP_SERVER@ edited in-file

basics

~20 s

A Nessus compliance scan runs audit files that test host configuration against a baseline such as a CIS benchmark, which a clean vulnerability scan does not prove. A custom audit file is edited before upload, not in the UI.

solid answer

~40 s

A vulnerability scan finds flaws and missing patches; a **compliance** (configuration) scan checks whether settings match a standard, and Tenable's guide is explicit that no vulnerabilities does not mean compliant. In Nessus 10.12 you add one or more **audit files** in a scan or policy's **Compliance** tab, for example through `Policy Compliance Auditing`, and each audit needs matching credentials: SSH for Unix, Windows credentials for Windows, Database credentials for a database audit. You can use a Tenable audit, a SCAP data stream, or a custom audit. Standard audits expose variables in the UI; in a **custom** audit you edit the variable in the file itself, replacing every `@NTP_SERVER@`-style placeholder in its `regex` and `expect` lines before upload. Compliance is not available in Essentials or Essentials Plus.

go deeper

for a junior

Recall that compliance scans check configuration against a baseline, while vulnerability scans look for flaws and missing patches.

for a middle

Explain where audit files are attached, which credential each needs, and how a custom audit's variables are changed in the file.

for a senior

Keep audit selection targeted, watch for plugin 214001 warnings, and use offline configuration audits where logging in is not allowed.

for a principal

Decide which baselines Nessus audits and which a separate configuration-as-code tool owns, so two sources do not disagree about one host.

## Two different questions about a host A **vulnerability scan** asks whether a host has known flaws: missing patches, vulnerable service versions, weak protocols. A **compliance scan**, which Tenable also calls a **configuration scan**, asks whether the host is configured the way a standard says it should be: password policy, audit settings, file contents, registry values, running processes. The Nessus 10.12 guide puts it plainly: a lack of vulnerabilities does not mean a server is configured correctly or compliant. Running both gives you how a server is configured, how it is patched and what is vulnerable. ## Where compliance checks live in Nessus Compliance checks are also called **audits**, and each is defined by an **audit file**. You add them in the **Compliance** tab of a scan or policy. The template built for this is `Policy Compliance Auditing`, which audits system configurations against a known baseline; other compliance templates include `Audit Cloud Infrastructure`, `MDM Config Audit`, `Offline Config Audit` (which audits network-device configuration files instead of scanning the device) and the legacy `SCAP and OVAL Auditing`. If a scan is based on a user-defined policy, its Compliance settings can be changed only in that policy. Edition matters: **compliance templates and custom audit uploads are not available in Nessus Essentials or Essentials Plus**; they start at Nessus Professional. ## Each audit needs its own credentials A compliance check reads configuration from inside the target, so the guide lists the credential type each audit requires. A few examples: | Compliance check | Required credentials | |---|---| | Unix, Unix File Contents | SSH | | Windows, Windows File Contents | Windows | | Microsoft SQL DB, Oracle DB, PostgreSQL DB | Database | | Cisco IOS, Juniper Junos | SSH | | Amazon AWS, Microsoft Azure, Google Cloud Platform | the provider's own credential type | | VMware vCenter/vSphere | VMware vCenter API or VMware ESX SOAP API | An audit attached without its credential cannot read what it is meant to evaluate. ## Three kinds of audit file When you configure Compliance settings you can use: 1. A **Tenable-created audit file** from the Tenable downloads page; the scanner's **audit warehouse** of published audits updates when you upgrade Nessus, or manually from an archive with `nessuscli update <tar.gz file name>`. 2. A **SCAP data stream**, which must contain full SCAP content (OVAL and XCCDF) or standalone OVAL content. 3. A **custom audit file** created or customised for your environment, documented in the Nessus Compliance Checks Reference. ## Customising a custom audit file Standard audits let you set their variables in the Nessus UI. The guide's example is a CIS CentOS 6 Server L1 v3.0.0 audit, where the UI offers a parameter called **Network Time**. **Custom audit files do not expose their variables in the UI**, so you change them in the file before uploading: - find the field's variable name (for Network Time it is `NTP_SERVER`); - search for it wrapped in at-signs, `@NTP_SERVER@`; the example has four hits, two `regex` lines and two `expect` lines; - replace each occurrence with your value, for example `192.0.2.0`; - repeat for every variable you need to change, then upload through **Compliance > Filter Compliance: custom > Add File**. Missing one occurrence leaves a check testing for a different value than the rest of the audit. ## Running audits well - Keep audit selection targeted: the guide warns that the number of audit files in one `Policy Compliance Auditing` scan is limited by the runtime and memory they need, and exceeding it can produce incomplete or failed results. - Watch for **`Compliance Plugin Errors: <plugin name>`** results, posted as a WARNING by plugin **214001** (Compliance Status) when a plugin hit an error or could not report issues. - Remember that SCAP auditing sends an executable to the remote host, which endpoint security software may block. ## Legacy SCAP content and offline audits The `SCAP and OVAL Auditing` template is retained for backward compatibility. It supports SCAP 1.2 and earlier, which is not compatible with operating systems such as Windows 10 and Windows 11 that require SCAP 1.3 or later, so a modern benchmark belongs in an audit file rather than in that template. For network devices that do not support secure remote access, or that the scanner cannot reach, `Offline Config Audit` evaluates an uploaded configuration file instead of the live device. Aggregated across an estate, compliance results let auditors spot trends in non-compliant systems and fix controls at scale rather than host by host.

  • A Nessus Policy Compliance Auditing scan with many audit files returns partial results. What do you check?
    Tenable warns that the number of audit files in one scan is limited by the runtime and memory they need, and exceeding it can produce incomplete or failed results. Narrow the audits to the scan's scope, split them across scans, and look for `Compliance Plugin Errors` warnings from plugin 214001.
  • You upload a custom CIS audit file to Nessus and the Network Time option is missing from the UI. Why?
    Custom audit files do not expose their variable parameters in the Nessus UI. You edit the variable, here `NTP_SERVER`, directly in the file by replacing each `@NTP_SERVER@` occurrence, then upload it again.
  • Can Nessus check compliance on a network device you are not allowed to log in to?
    Yes, through the `Offline Config Audit` template, which audits the device's configuration file instead of scanning the device over the network or with credentials. Tenable recommends it for devices without secure remote access or that scanners cannot reach.

saying these in an interview costs you the question

  • A clean Nessus vulnerability scan proves the host is CIS compliant.
  • Nessus Essentials can run CIS compliance audits with a custom audit file.
  • Custom audit file variables can be edited in the Nessus UI after upload.
  • A compliance audit runs fine without credentials for the target platform.
  • Adding more audit files to one scan never affects its results.