How to Answer Vulnerability Scanning Questions

Your customer asked: “Do you perform vulnerability scanning?”

The short answer

Vulnerability scanning generally means using tools or services to identify known weaknesses in systems, software, or configurations. Confirm the actual scope, frequency, and ownership before answering, and do not substitute penetration testing—or vice versa—as if they were the same activity.

Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.

What the customer is really asking

Understand the question before you answer it.

The reviewer wants to know whether your company has a repeatable way to identify technical weaknesses. They may ask separately how findings are prioritized, tracked, and remediated.

How to answer accurately

Start with the version that matches reality.

1

If scanning is performed

State the systems or environment in scope and the cadence only if verified. You can describe internal or third-party tooling without exposing sensitive scan details.

2

If a vendor performs scans for you

Describe the vendor-supported activity and your company's role in reviewing or remediating results.

3

If you only have a penetration test

Do not automatically answer “yes.” A periodic penetration test and recurring vulnerability scanning are different activities.

A useful answer structure

Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.

Evidence that may help

These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.

  • Recent scan summary
  • Scanner configuration or schedule
  • Finding and remediation records
  • Third-party service report

What not to say

  • That a penetration test proves recurring vulnerability scanning.
  • That all systems are scanned when only a subset is in scope.
  • That scanning means every identified vulnerability was fixed.

How Oredra handles this

Answer it once. Keep the truth behind the answer.

Oredra can store vulnerability scanning and penetration testing as separate practices so questionnaire reuse does not blur the distinction.

Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.

Authoritative references

Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.

Related questionnaire questions