skip to content

What can a host agent, a network vulnerability scanner and a passive traffic sensor each see when detecting vulnerabilities, and what does each miss?

level: middleimportance: should knowfreq 22%

answer

  1. three vantage points
  2. inside, along the path, listening
  3. devices that cannot run software
  4. only what talks, only in cleartext

basics

~20 s

An agent reads the host from inside — packages, configuration — wherever the host goes, but only where it is installed. A network scanner sees what is reachable and how services answer. A passive sensor infers software from observed traffic, touching nothing.

solid answer

~50 s

An **agent** runs on the host and performs local checks: installed packages, patch level, configuration, with no stored network credentials and no route from a scanner needed, and it keeps reporting from laptops and short-lived cloud instances wherever they are. It misses every device it cannot be installed on — network gear, printers, appliances, unmanaged hosts — and does not see what the network actually exposes. A **network scanner** probes from a vantage point: it finds devices nobody installed anything on and sees services as a client on that path would, with credentials adding local depth; it misses whatever it cannot reach. A **passive sensor** watches a copy of traffic and infers hosts, services and versions from what crosses the wire, adding no load to anything — but it only sees hosts that talk, on segments it watches, and only what is visible in cleartext. Programmes combine them because each covers the others' blind spots.

go deeper

for a junior

Recall the three vantage points: an agent inside the host, a network scanner probing from a point in the network, a passive sensor listening to copied traffic.

for a middle

Explain what evidence each collects and what that implies: local checks without stored credentials, the reachable-path view, and inference from cleartext traffic with no load.

for a senior

Use the blind spots to diagnose disagreements between tools — unmanaged devices, unreachable ranges, silent hosts, encrypted traffic — and say which evidence wins when findings conflict.

for a principal

Frame the combination as a coverage design: which asset classes each approach owns, and how you notice the devices none of the three is seeing.

## Three vantage points A vulnerability finding is only as good as the place the evidence was collected from. Detection tools sit in one of three places: | | Host agent | Network scanner | Passive sensor | |---|---|---|---| | Where it runs | On the host itself | On a machine with a route to targets | On a mirrored copy of traffic | | How it decides | Local checks on installed software and configuration | Remote probes, plus local checks when given credentials | Inference from banners, versions and behaviour seen on the wire | | Finds unknown devices | No | Yes, if reachable | Yes, if they talk | | Sees what is reachable over the network | No | Yes, from its own path | Partly, from observed connections | | Load on the target | Small, continuous | Bursts during a scan | None | ## The agent: the inside view A lightweight agent installed on the host runs local checks and reports results to a central service. - **Strengths.** It reads the same evidence a credentialed scan reads — installed packages, patch level, configuration — without the programme storing network credentials for the host or opening a route from a scanner. It keeps reporting from laptops off the corporate network and from short-lived cloud instances that may not exist when a scan runs. - **Blind spots.** It sees nothing it is not installed on: switches, routers, printers, appliances, embedded devices, and any host nobody knew to install it on. It also sees the host's own configuration rather than what a client can actually reach, so a firewall in the path, or a service exposed through a load balancer, is outside its view. - **Check coverage.** Agents run local checks; flaws that can only be detected by talking to a service over the network are not something an agent can confirm on its own. ## The network scanner: the path view A network scanner, often a physical or virtual scanner appliance placed in the network, connects to targets. - **Strengths.** It finds devices nobody installed anything on, and it sees services as a client on its path sees them: which ports answer, what a service presents to a connecting client. Given credentials, it adds the inside view for hosts that accept a login. - **Blind spots.** It sees only what it can reach when it runs: hosts behind filtering, hosts that are switched off or off the network during the scan, and ranges it was never pointed at stay invisible. Without credentials, its verdicts on reachable hosts are inferences from banners. ## The passive sensor: listening only A passive sensor receives a copy of traffic, for example from a mirror port or a network tap, and never sends anything to the hosts it describes. - **Strengths.** Zero load on the target, which makes it the gentlest way to learn about devices that tolerate no probing. It sees any host that communicates across the watched segment, including ones that appear briefly between scans, and it sees client software as well as servers when they announce versions in cleartext. - **Blind spots.** A silent host is invisible. Segments without a sensor are invisible. Encrypted sessions hide application-layer banners and version strings, so inference falls back to whatever stays in cleartext. And like a remote scan, its verdicts are inferences from what the software says about itself. ## Why the answers disagree, and how they combine The three views routinely produce different findings for the same host, because they collect different evidence. A sensible design gives each the job it is best at: 1. **Agents** on every host the organisation manages and can install software on, especially mobile and short-lived ones. 2. **A network scanner** for everything that cannot run an agent, and to see what is actually exposed on the paths that matter. 3. **A passive sensor** where probing is unwelcome, and to reveal devices the other two never knew existed. Where the views overlap, compare the evidence each finding cites: an installed package version from inside generally outranks a banner seen from outside. ## What to take away Agent, network scanner and passive sensor answer three different questions: what is installed here, what can be reached from there, and what has been seen talking. None of them alone covers an estate, and a candidate who can name each one's blind spot can explain most coverage surprises.

  • An agent reports a host clean, but a network scan reports a vulnerable service on it. How can both be right?
    They read different evidence. The network check may be inferring from a banner that the installed package record contradicts, or the service may come from software outside the agent's local checks, such as a self-contained build or an appliance image. Compare the evidence each finding cites: an installed version from inside versus a banner or response from outside.
  • What can a passive sensor find that both an agent and a scheduled network scan miss?
    A device that talks but is never there at the right moment or never had anything installed: a visitor's laptop, a short-lived host that was off when the scan ran, a system nobody knew about. Anything sending traffic across a watched segment is seen, including client software versions visible in cleartext. Silent hosts and unwatched segments stay invisible.

saying these in an interview costs you the question

  • An agent sees everything a network scan sees, so network scans are obsolete.
  • A passive sensor can read versions inside encrypted sessions.
  • A network scanner finds every device, including ones it cannot reach.
  • A passive sensor probes hosts, only very gently.
  • An agent needs network credentials stored on a scanner to work.