skip to content

Vulnerability Assessment

Host and network scanners that test assets against a vulnerability feed, credentialed or from outside. Interviewers ask how a scanner decides a finding and how you run one without breaking hosts.

on this pageshow

explore

questions

28

In Nessus, what is a plugin, and what do its plugin ID, family and type tell you about a finding?

level: juniorimportance: must knowfreq 32%

answer

  1. the unit Nessus detects with
  2. Tenable research, its own scripting language
  3. numeric ID, family for selection
  4. remote, local, combined, settings, summary

basics

~20 s

A Nessus plugin is a NASL program from Tenable, usually testing for one issue. Its numeric ID names the finding, its family groups it for selection in a policy, and its type says how it gathered evidence.

solid answer

~40 s

A plugin is the unit Nessus detects with: a NASL program from Tenable's research team that carries the vulnerability description, a generic remediation and the test itself. Every finding in a Nessus report is a plugin result on a host, so the **plugin ID** is the stable name you track, exclude or search for. The **family** (for example `Denial of Service`) is how a policy enables or disables plugins in bulk. The **type** tells you how much to trust the result: `remote` collects over the network without host credentials, `local` logs in through a service such as SSH or SMB, `combined` uses both, while `settings`, `summary`, `third party` and `reputation` plugins support the scan rather than test for a flaw. Standalone Nessus refreshes the plugin set every 24 hours by default.

go deeper

for a junior

Recall that a plugin is one NASL detection program, that the plugin ID names a finding and that families group plugins for selection.

for a middle

Explain the plugin types, especially remote against local against combined, and how a family's enabled, disabled or Mixed state scopes a policy.

for a senior

Read the type and the evidence note before trusting a finding, and talk about tracking, excluding and filtering results by plugin ID.

for a principal

Frame plugin IDs as the stable key between Nessus and the rest of a vulnerability programme, and say where CVE-keyed reporting will disagree with them.

## What a plugin is Tenable Nessus does not ship one monolithic scanner engine with hard-coded tests. Tenable's research staff write a separate program for each issue they want Nessus to detect, and the Nessus 10.12 user guide calls each of these programs a **plugin**. Plugins are written in Tenable's proprietary **Nessus Attack Scripting Language (NASL)**. Each one carries three things: - the **vulnerability information** shown in the report (synopsis, description, references); - a **generic set of remediation actions** (the Solution section); - the **algorithm** that tests the target for the issue. Nessus also uses plugins to collect configuration information from authenticated hosts for configuration audits, so not every plugin reports a vulnerability. When Nessus is registered it downloads the plugins and compiles them into an internal database. While that compilation runs you cannot create or launch scans, or create or view policies. A standalone scanner checks for updated plugins every **24 hours** by default; `nessuscli update --plugins-only` forces a plugin-only update from the command line. ## The fields that identify a plugin Open any finding and the **Plugin Information** block names the plugin precisely: | Field | What it tells you | |---|---| | `ID` | The plugin's numeric identifier, stable across scans and reports | | `Version` | The plugin's current version; the `Modified` date shows when it last changed | | `Type` | How the plugin operates when a scanner runs it | | `Published` / `Modified` | When the plugin first appeared and last changed | The ID is the handle every other Nessus feature uses: you search for it in a policy's Plugins tab, filter results by it, and some plugins exist only to report on the scan itself. Plugin **19506** (Nessus Scan Information), for example, summarises how the scan ran rather than reporting a flaw. ## Plugin families Plugins are grouped into **families**. A family is a selection unit, not a severity tier: in a policy's Plugins tab you enable a whole family (green), disable it (gray), or open it and pick individual plugins, which turns the family purple and marks it **Mixed**. Two family names appear in the 10.12 guide itself: - `Denial of Service`, which Tenable warns contains plugins that could cause outages unless **Safe Checks** is enabled; - `ESX Local Security Checks`, whose checks use ESXi package details collected with VMware credentials. ## Plugin types: how the evidence was gathered The `Type` field is the one that matters when you judge a finding: 1. `remote` — does not require local host credentials; collects information over the network through banner checks, testing for a patch, or exploiting a vulnerability. Some remote plugins sign in to a service, but they do not require local host credentials. 2. `local` — authenticates to the target through a service such as SMB or SSH and extracts information. 3. `combined` — uses both, and still reports what it can from the remote part when local checks are unavailable. 4. `settings` — defines settings other plugins use during the scan. 5. `summary` — summarises data other plugins collected. 6. `third party` — runs a third-party application. 7. `reputation` — uses a third-party reputation service. Some plugin pages on the Tenable plugins site carry the note "Nessus has not tested for this issue but has instead relied only on the application's self-reported version number". That note marks a finding inferred from a version string; why such inferences go wrong is a general scanning question, not a Nessus one. ## What else a plugin result carries Below the Plugin Information block, a result shows **Risk Information** (VPR, EPSS, Risk Factor and CVSS v2.0, v3.0 and v4.0 base scores and vectors), **Vulnerability Information** (CPE, whether an exploit is available, patch and vulnerability publication dates) and **Reference Information** (CVE, CWE, CERT, IAVA, BID and similar). A single plugin can list several CVEs, so a plugin ID and a CVE are not interchangeable keys. ## Why interviewers ask A candidate who has run Nessus talks about findings by plugin ID, knows that a family is how a policy is scoped, and reads the type before trusting a result. A candidate who has only read about it tends to treat the plugin ID as a CVE number or to describe families as severity buckets.

  • Why would you exclude or track a finding by plugin ID rather than by CVE in Nessus?
    The plugin ID is what Nessus itself keys on: policies select plugins, filters match `Plugin ID`, and a plugin's Reference Information can list several CVEs at once. Tracking by CVE can merge or split findings in ways Nessus does not, so the plugin ID is the stable join between scans.
  • A finding's plugin page says Nessus relied only on the application's self-reported version number. What does that tell you?
    That the plugin inferred the issue from a reported version rather than testing for it, so the result is only as good as that version string. How to confirm or dispute such an inference is a general scanning question; the Nessus-specific point is that the plugin page tells you which kind of evidence you are holding.

saying these in an interview costs you the question

  • A Nessus plugin ID is just the CVE number in another format.
  • Plugin families are severity tiers such as critical, high and medium.
  • Nessus plugins are compiled binaries written in Python.
  • A remote-type plugin logs in over SSH to read installed packages.
  • Every Nessus plugin reports a vulnerability.
open as a page

In Qualys VMDR, what is a QID, and why is it not the same thing as a CVE?

level: juniorimportance: must knowfreq 30%

basics

~20 s

A QID (Qualys ID) is the number of one detection in the Qualys KnowledgeBase. A CVE names a published flaw; a QID is Qualys's test and verdict, may list several CVEs, and can carry none at all.

open as a page

How does an unauthenticated network vulnerability scan decide a host is vulnerable, and how does a credentialed scan decide differently?

level: juniorimportance: must knowfreq 50%

basics

~20 s

An unauthenticated scan infers from what services expose on the network: banners, version strings, protocol behaviour. A credentialed scan logs in and reads installed package versions and configuration, so it decides from the host's own record instead of a guess.

open as a page

What does a quarterly point-in-time vulnerability scan miss that continuous assessment of the same estate catches?

level: juniorimportance: must knowfreq 34%

basics

~20 s

A point-in-time scan proves the state of the hosts it reached on the day it ran. It misses hosts that came and went between runs, changes made since, and newly disclosed flaws in software it already saw.

open as a page

How does the Greenbone Community Feed differ from the Greenbone Enterprise Feed, and is the free feed really delayed behind the paid one?

level: middleimportance: must knowfreq 24%

basics

~20 s

Both Greenbone feeds publish daily. The free Community Feed carries the most important VTs plus basic configs, without VTs for enterprise products and with no warranty; the commercial Enterprise Feed adds those VTs, compliance checks, more report formats and an SLA.

open as a page

In Greenbone Community Edition, what do gvmd, ospd-openvas, openvas-scanner and gsad each do, and which protocols connect them?

level: middleimportance: must knowfreq 18%

basics

~20 s

gvmd is the manager: it offers GMP, stores everything in PostgreSQL and drives the scanner over OSP. ospd-openvas launches openvas-scanner, which runs the VTs using Redis; gsad serves the web interface and speaks GMP to gvmd.

open as a page

A vulnerability scan of a hardened Linux fleet reports dozens of critical findings the owners insist are already patched — how did the scanner most likely reach them, and how do you confirm it?

level: seniorimportance: must knowfreq 40%

basics

~20 s

Most likely by banner inference: distributions that backport security fixes patch the code without raising the upstream version, so the service still advertises an affected version. Confirm by reading the installed package release and changelog against the distribution's advisory.

open as a page

How do you vulnerability-scan a segment of fragile operational-technology controllers and legacy hosts without causing an outage?

level: seniorimportance: must knowfreq 28%

basics

~20 s

Treat the scan as a change: agree a window, an owner on call and a stop condition; scan from inside with non-intrusive checks, low concurrency and a narrow port list; trial on a spare first; leave untouchable devices to passive observation.

open as a page

When a colleague says they run OpenVAS, what might they mean, and how do OpenVAS, GVM and Greenbone Community Edition relate?

level: juniorimportance: should knowfreq 20%

basics

~20 s

OpenVAS can mean just the scan engine or the whole framework. The framework was renamed GVM after OpenVAS 9, and since 2022 Greenbone calls its open-source releases Greenbone Community Edition, with the OpenVAS Scanner as one component.

open as a page

In Nessus Professional, what does a compliance scan with an audit file check that a vulnerability scan does not, and how do you customise one?

level: middleimportance: should knowfreq 17%

basics

~20 s

A Nessus compliance scan runs audit files that test host configuration against a baseline such as a CIS benchmark, which a clean vulnerability scan does not prove. A custom audit file is edited before upload, not in the UI.

open as a page

In Nessus, how does a Tenable-provided scan template differ from a user-defined policy, and what can a scan built on that policy no longer change?

level: middleimportance: should knowfreq 22%

basics

~20 s

A Nessus scan template is a Tenable-provided starting point with fixed settings and presets; a policy is your saved configuration built from one. A scan based on a policy cannot change its Discovery, Assessment or Advanced settings in the scan.

open as a page

Before replacing Qualys scanner appliance scans with Cloud Agents, how do you check which QIDs the agents can actually detect?

level: middleimportance: should knowfreq 22%

basics

~10 s

Search the Qualys KnowledgeBase with Supported Modules set to CA-Windows Agent or CA-Linux Agent, or query vulnerabilities.vulnerability.supportedBy. Any QID you rely on that is missing from that list still needs scanner appliance scans.

open as a page

What can a host agent, a network vulnerability scanner and a passive traffic sensor each see when detecting vulnerabilities, and what does each miss?

level: middleimportance: should knowfreq 22%

basics

~20 s

An agent reads the host from inside — packages, configuration — wherever the host goes, but only where it is installed. A network scanner sees what is reachable and how services answer. A passive sensor infers software from observed traffic, touching nothing.

open as a page

Why does a vulnerability scanner's verdict depend on its vendor-maintained check feed, and what does feed lag mean for a clean scan run the day after a disclosure?

level: middleimportance: should knowfreq 20%

basics

~20 s

A scanner detects only what its checks describe, and checks arrive through a vendor-maintained feed. Until a check for a new flaw is written, published and downloaded, nothing reports it, so a next-day clean scan says nothing about that flaw.

open as a page

What separates a safe vulnerability-scanner check from an intrusive or denial-of-service check, and what does restricting a scan to safe checks cost in accuracy?

level: middleimportance: should knowfreq 28%

basics

~20 s

A safe check decides from observation — a banner, a version, a harmless response — while an intrusive check exercises the flaw and can crash or change the service. Safe-only scans replace proof with inference: more uncertain findings, some flaws missed.

open as a page

A vulnerability scan report lists 2,000 hosts assessed; how do you find the hosts it never assessed at all?

level: middleimportance: should knowfreq 22%

basics

~20 s

Diff the scan's assessed-host list against independent inventories: cloud and virtualisation APIs, DHCP leases, DNS, directory computer accounts, switch and flow data. Anything in those sources that is missing, silent or only partly assessed in the scan is a coverage gap.

open as a page

Why does a vulnerability scanner probing a segment through a stateful firewall report a different picture than one placed inside it?

level: middleimportance: should knowfreq 14%

basics

~20 s

Devices in the path change what the scanner sees: firewalls drop or answer probes, intrusion prevention can block the scanner mid-run, and address translation blurs host identity. Results mix the firewall's policy with the hosts' real state.

open as a page

A Nessus credentialed scan of Linux servers returned far fewer findings than expected — which Nessus plugins and settings show whether the credentials actually worked?

level: seniorimportance: should knowfreq 26%

basics

~10 s

Read plugin 19506 (Nessus Scan Information): on Linux, Credentialed checks : yes needs a login and a retrieved package inventory. Plugin 21745 reports failed SSH or Windows logins but is silent on success.

open as a page

After a fresh Greenbone Community Edition source build and a greenbone-feed-sync run, GSA lists no scan configs and a test scan finds nothing: what is happening, and how do you confirm it?

level: seniorimportance: should knowfreq 9%

basics

~20 s

Downloading the feed is only half a sync: ospd-openvas and gvmd must then load it, which can take hours, and scan configs also need a Feed Import Owner set in gvmd. Confirm with both daemons' load messages.

open as a page

Two Qualys VMDR assets carry the same critical QIDs, yet one has a TruRisk Score of 900 and the other 350 — what explains the gap?

level: seniorimportance: should knowfreq 18%

basics

~20 s

TruRisk Score multiplies the asset's criticality (ACS, 1 to 5) by severity-weighted QDS averages, capped at 1000. Identical QIDs on an ACS 5 and an ACS 2 asset differ about 2.5 times. Mitigation controls and external exposure explain the rest.

open as a page

Why is a finding's absence from the next scheduled host scan not proof of a fix, and what evidence closes it?

level: seniorimportance: should knowfreq 18%

basics

~20 s

Absence only shows nothing was reported: the host may have been unreachable or unauthenticated, or the check never ran. Close a fix on a targeted rescan in which the same check ran with the same access and found the flaw absent.

open as a page

After a scan-account password rotation, critical findings on 40 hosts fell by two-thirds overnight; what most likely happened, and how should scan credentials be run?

level: seniorimportance: should knowfreq 21%

basics

~20 s

The scanner most likely stopped logging in: a failed authenticated login degrades to remote checks, which find far less, so the drop is lost visibility, not remediation. Hold scan credentials in a vault, rotate through it, and alert on per-host authentication status.

open as a page

In Nessus 10.12, how do Essentials, Essentials Plus, Professional and Expert differ, and how is a host limit counted?

level: juniorimportance: nice to knowfreq 11%

basics

~20 s

In Nessus 10.12, Essentials scans up to 5 hosts with a 30-day-delayed feed, Essentials Plus 20 with a real-time feed, and neither has compliance. Professional adds compliance, Expert adds web app, attack-surface and IaC scanning. Discovery-only hosts never count.

open as a page

In Nessus, a newly published plugin never ran in a scan using your saved policy — what decides whether new plugins join an existing policy?

level: middleimportance: nice to knowfreq 9%

basics

~20 s

In a family-based Nessus policy, a new plugin runs only if the scanner has it and its family allows it: enabled families take new plugins, disabled ones do not, and a Mixed family follows its padlock.

open as a page

How do you drive a Greenbone scan from a script over GMP with gvm-tools, and when would you pick gvm-cli over gvm-script?

level: middleimportance: nice to knowfreq 12%

basics

~20 s

gvm-tools clients speak GMP, gvmd's XML protocol: create a target, create a task with a scan config and scanner, start it, poll get_tasks, then fetch the report. gvm-cli sends raw XML for simple shell jobs; gvm-script runs Python for anything with logic.

open as a page

In Greenbone's OpenVAS, how does a NASL NVT differ from a Notus local security check, and why did Greenbone introduce Notus?

level: middleimportance: nice to knowfreq 6%

basics

~20 s

An NVT is a NASL script, identified by an OID, that openvas runs against a host. Notus replaces script-per-check local security checks with one comparison of the installed packages against a list of vulnerable versions for that OS.

open as a page

A scheduled Qualys scan of 10.20.0.0/16 fails with 'A virtual or physical scanner appliance is needed' — why, and what fixes it?

level: middleimportance: nice to knowfreq 12%

basics

~20 s

Qualys's external cloud scanners scan from the internet and will not scan private addresses. A 10.x target needs an internal scanner appliance, deployed where it can route to that range and selected for the scan.

open as a page

A Qualys AWS connector lists 1,200 running EC2 instances, but only 900 have VMDR findings — how do you find and close the gap?

level: seniorimportance: nice to knowfreq 9%

basics

~20 s

Query the connector's inventory for running instances without an agent (aws.ec2.hasAgent: false AND aws.ec2.instanceState: RUNNING). Then find installed agents that stopped checking in. Close the gap by provisioning agents through the connector, and scan from appliances what cannot host one.

open as a page