In Nessus, how does a Tenable-provided scan template differ from a user-defined policy, and what can a scan built on that policy no longer change?
answer
- starting points versus saved configurations
- Discovery, Vulnerabilities, Compliance categories
- preconfigured Scan Type presets
- User Defined tab, .nessus export
- settings locked to the policy
basics
~20 sA Nessus scan template is a Tenable-provided starting point with fixed settings and presets; a policy is your saved configuration built from one. A scan based on a policy cannot change its Discovery, Assessment or Advanced settings in the scan.
solid answer
~40 sTenable ships **scanner templates** in three categories: Discovery (such as `Host Discovery`), Vulnerabilities (such as `Basic Network Scan`, `Advanced Scan`, `Credentialed Patch Audit`) and Compliance (such as `Policy Compliance Auditing`). A Tenable template lets you change only the settings its type includes, and several preconfigure settings per **Scan Type**: `Basic Network Scan` on `Default` runs at most 30 hosts, 4 checks per host and a 5-second read timeout. A **policy** is your own configuration, created from a template under Policies, shown in the **User Defined** tab, and exportable as a `.nessus` file. When a scan uses a policy, its Discovery, Assessment and Advanced settings, and Compliance for a user-defined policy, can be edited only in the policy, so one change reaches every scan that uses it.
go deeper
Recall the three scanner template categories and that a policy is a saved configuration you build from a template and reuse.
Explain what a Scan Type preconfigures, why Advanced Scan exposes more, and which settings a policy-based scan can no longer change.
Design policies so one change reaches the right scans, and recognise a missing setting in a scan as a policy-based scan rather than a bug.
Weigh a few shared policies, which change everywhere at once, against many per-team policies, which drift apart and multiply review effort.
## Two layers of scan configuration Tenable Nessus separates **what a scan does** from **what it scans and when**. A scan holds targets, a name and an optional schedule; the technical behaviour comes from either a Tenable-provided **scan template** or a **user-defined policy**. Interviewers ask about the difference because it decides who can change a scan's behaviour and how far a change reaches. ## Tenable-provided scan templates When you click **New Scan**, Nessus 10.12 shows its scanner templates in three categories: - **Discovery** — `Host Discovery`, `Ping-Only Discovery` and, in Nessus Expert, `Attack Surface Discovery`. Hosts found only by a discovery scan do not count towards a host-limited licence. - **Vulnerabilities** — `Basic Network Scan`, `Advanced Scan`, `Advanced Dynamic Scan`, `Credential Validation`, `Credentialed Patch Audit`, `Malware Scan` and targeted templates such as `Active Directory Starter Scan`. - **Compliance** — `Policy Compliance Auditing`, `Audit Cloud Infrastructure`, `Offline Config Audit`, `Internal PCI Network Scan` and others; none of these is available in Nessus Essentials or Essentials Plus. Nessus Manager adds **agent templates**, and Nessus Expert adds **web app templates**. A Tenable template is deliberately narrow: you can modify only the settings included for that template type. Several templates also offer a **Scan Type** that applies preconfigured settings: | Template | Scan Type | Preconfigured performance | |---|---|---| | `Basic Network Scan` | `Default` | 30 simultaneous hosts, 4 checks per host, 5-second network read timeout | | `Basic Network Scan` | `Scan low bandwidth links` | 2 hosts, 2 checks per host, 15-second timeout, slow down on congestion | | `Basic Network Scan` | `Custom` | all defaults, editable | | `Advanced Scan` | — | all defaults | Note the trap: the Advanced settings table lists `Max simultaneous checks per host` with a default of **5**, while the `Default` scan type of `Basic Network Scan` presets **4**. The preset belongs to the template, not to the setting. `Advanced Scan` has the same defaults as `Basic Network Scan` but exposes every option; the guide warns that misconfiguring it can cause asset outages or network saturation. `Advanced Dynamic Scan` replaces hand-picked plugin families with **dynamic plugin filters**. ## User-defined policies A **policy** is a saved set of configuration options. You create one under **Scans > Policies > New Policy** by picking a policy template, configuring it and saving it. Its settings span the same tabs a scan has: 1. **Basic** — name, description, private or shared visibility. 2. **Discovery** — host discovery method, port scan range, service detection. 3. **Assessment** — scan type (network, web app, malware), accuracy settings, brute-force options. 4. **Report** — verbosity and processing options. 5. **Advanced** — performance (max hosts, max checks, network timeout), `Enable Safe Checks`, debug logging. 6. **Credentials** — Windows, SSH, database, HTTP, SNMP and others. 7. **Plugins** — families and individual plugins. 8. **Compliance** — audit files such as CIS benchmarks and DISA STIGs. Saved policies appear in the **User Defined** tab when you create a scan, so a policy becomes a reusable template of your own. A policy can be **exported as a `.nessus` file** and imported into another Nessus installation; a Nessus DB file cannot be imported as a policy. ## What a policy-based scan cannot change The user guide states the rule tab by tab: if a scan is based on a policy, you cannot configure its **Discovery**, **Assessment** or **Advanced** settings in the scan, and if it is based on a user-defined policy you cannot configure its **Compliance** settings there either. You change them in the policy. The consequences: - one edit to the policy reaches every scan built on it, which is the point of using one; - a team that wants one scan to run slower or skip a family needs a second policy, not a scan-level tweak; - an engineer who opens a scan to raise the network timeout and finds the field missing is looking at a policy-based scan. ## Choosing between them Use a Tenable template when its presets fit and you want Tenable's recommended defaults. Build a policy when several scans must share a tuned configuration, when an audited configuration must be exported to another scanner, or when you need settings a template does not expose.
- You need one Nessus scan of a slow branch-office link to use gentler performance settings than the shared policy. What do you do?Because a policy-based scan cannot change its Advanced settings, you either create a second policy with lower `Max simultaneous hosts per scan` and checks per host, or build that scan from `Basic Network Scan` with the `Scan low bandwidth links` scan type, which presets 2 hosts, 2 checks per host and a 15-second timeout.
- How do you move a tuned Nessus policy from a lab scanner to a production scanner?Export the policy from Scans > Policies; it downloads as a `.nessus` file. Import that file on the other installation under Policies > Import, then review and adjust its settings there. A Nessus DB export cannot be imported as a policy.
saying these in an interview costs you the question
- You can override any policy setting from inside a scan that uses the policy.
- A Tenable template exposes every Nessus setting, exactly like Advanced Scan.
- Basic Network Scan on its Default type runs five checks per host.
- A Nessus policy is a list of targets and a schedule.
- Compliance templates are available in every Nessus edition, including Essentials.