What is vulnerability scanning?
Vulnerability scanning is the automated checking of systems, containers, and applications for known security weaknesses, such as missing patches or insecure configuration. Scanners compare what they find against databases of known vulnerabilities (CVEs). Scans run on a schedule or continuously.
What the buyer is really asking
Say what gets scanned (hosts, containers, cloud configuration, web app), how often, and with what tool. Continuous scanning built into your cloud or CI counts. Mention who reviews the results.
Other ways buyers ask it
Every one of these wants the same answer:
- “How often do you conduct automated vulnerability scans?”
- “Do you scan infrastructure and containers for vulnerabilities?”
- “What vulnerability scanning tools do you use?”
Evidence to have ready
- Scanner configuration and schedule
- A recent scan summary
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.