Scanning tools compare system configurations and software versions against databases of known vulnerabilities, producing prioritized findings. Scans may run continuously, weekly, or on a defined schedule.
It differs from penetration testing by identifying known issues rather than attempting exploitation.
Alternative Names:
Vulnerability Assessment, Security Scanning
Why it Matters?
Scanning identifies known vulnerabilities while penetration testing finds what an attacker could actually do with them, which is why both appear in mature programs. The metric that matters is remediation time rather than scan frequency, since finding vulnerabilities without closing them provides no protection. Asking a vendor for its mean time to remediate critical findings is more informative than asking whether it scans.
Frequently Confused with
Related terms
Frequently asked questions
How does scanning differ from penetration testing?
What metric matters most?





