FAQ
Vulnerability Scanning & Hardening FAQ
Everything you need to know about vulnerability scanning, hardening and exposure management with NetGuard.
What is a vulnerability scanner?
A vulnerability scanner is software that automatically checks servers, network devices, endpoints and web applications for known security weaknesses — such as missing patches (CVEs), insecure configurations, default passwords and exposed services — and reports them with a severity rating and remediation advice.
What is system hardening?
System hardening is the process of reducing a system's attack surface by removing unnecessary services, closing unused ports, enforcing strong authentication and applying secure configuration settings. Hardening is usually measured against a baseline such as the CIS Benchmarks.
What is the difference between vulnerability scanning and penetration testing?
Vulnerability scanning is automated, broad and continuous: it finds known weaknesses across your whole environment. Penetration testing is a manual, time-boxed exercise where experts try to exploit weaknesses. The two complement each other — continuous scanning keeps your risk low between penetration tests.
What is exposure management?
Exposure management goes beyond listing vulnerabilities. It continuously discovers all assets, assesses vulnerabilities and misconfigurations, prioritizes them by exploitability and business impact, and tracks remediation until risk is verified as reduced.
Can NetGuard be deployed on-premises?
Yes. NetGuard can run entirely inside your data center, including isolated and air-gapped networks, so scan data never leaves your infrastructure. A private-cloud option is also available.
Will scanning affect my production systems?
NetGuard uses safe checks by default, with bandwidth limits, concurrency controls and scan windows, so you can assess production environments without disrupting them.
Which standards does NetGuard support?
Findings are mapped to CVE, CVSS and OWASP Top 10, and hardening audits follow CIS Benchmarks. Reports can be mapped to ISO/IEC 27001, PCI DSS and NIST controls.
Are reports available in Persian?
Yes. Dashboards and reports are available in both Persian and English, including executive summaries for management and detailed technical reports for engineers.
Find out what attackers can see — before they do
Get a complimentary external exposure assessment and a prioritized report from our security engineers.

