T Techclick ← All lessons
Tenable · Evidence desk · Interactive lesson

Prove Tenable is scanning — first tool + proof field

01:40. Slack: “Is the scan actually running? Why is this host missing?” The weekly criticals look thin. Someone already typed “Tenable is down.” A screenshot of the Explore dashboard is not proof. This desk is five official surfaces — Explore asset, last scan, scanner / agent health, plugin / finding, scan job status — each mapped to one ticket, one first click, and one field you paste before you launch another Advanced Network Scan.

~20 min read · L2 primary · Quiz at end · Blog 1 · Factory

⚡ Quick Answer

How you prove Tenable is scanning: Explore asset, last scan, scanner/agent health, plugin finding, scan job status. Five tickets with first tool and one proof field.

After this page you can

Quick answer (say this out loud)

Explore → Assets answers “is this host even in the container?” Last Scan Time / Last Authenticated Scan / Last Licensed Scan answers “when did an assessment last land — and was it credentialed?” Sensors answers “is the Nessus scanner or Tenable Agent that should have hit this host Online, and when did it last connect?” Explore → Findings answers “is this Plugin ID New, Active, Fixed, or Resurfaced — and what is VPR?” Scans → Vulnerability Management Scans answers “is the job Initializing, Running, Publishing Results, Completed, Pending, or Aborted?” A green dashboard tile is not a host record. An empty weekly PDF is not a dead platform.

1. Why “is it scanning?” is five questions

Operators collapse five failures into one sentence. The IP was never observed as an asset. The last licensed scan is eighteen days old. The Pune Nessus scanner is Offline. Plugin 156999 is Fixed on this Asset ID but still on the PDF. The 02:00 job sat in Pending until Tenable aborted it at four hours. Those are five first clicks.

This page is the night-shift desk for proof. The factory taught completed ≠ authenticated ≠ exploitable. Here you learn the five tools you actually open, in order, when someone asks you to prove Tenable Vulnerability Management / Nessus is scanning — or to explain why a host is missing.

Hero · five tiles, one missing host
Night-shift operations desk with five glowing proof tiles for asset, last scan, scanner, plugin, and scan job
Notice: five tiles, not one “Tenable dashboard.” You pick the tile that matches the question, then you quote one field.
Interview line

If they say “prove Tenable is scanning,” do not say “I opened Explore.” Say: “I prove the host in Explore Assets with Asset Name + Last Seen, the assessment with Last Authenticated Scan vs Last Licensed Scan, the sensor with Status + Last Connect, the finding with Plugin ID + State, and the job with scan Status.”

2. Mental model — five proof tools

Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you launch a second scan of a box that was never in the target list.

1 · Asset

Explore → Assets (Hosts). Proves the record: Asset Name, Asset ID, IPv4 Addresses, Last Seen, Sources, Has Agent. Does not prove last licensed scan or a Plugin ID.

2 · Last scan

Same asset pane / columns: Last Scan Time, Last Authenticated Scan, Last Licensed Scan, Last Scan Target, Last Scan ID. Proves when an assessment last landed — and whether credentials or only discovery ran.

3 · Scanner / agent

Sensors → Nessus Scanners (Linked Scanners) or Nessus Agents → Linked Agents. Proves sensor life: Status (Online / Offline), Last Connect, Last Scanned, Health. Online ≠ it reached the subnet.

4 · Plugin / finding

Explore → Findings (Vulnerabilities). Proves one result: Plugin ID + State (New / Active / Fixed / Resurfaced) + VPR + Severity + First Seen. Empty list is data.

5 · Scan job

Scans → Vulnerability Management Scans. Proves the job: Status (Initializing → Running → Publishing Results → Completed), plus Scanner, Targets, Warnings. Pending is not Running.

Hard words, once

Last Licensed Scan = last scan with non-discovery plugins (counts toward license). Managed = assessed in 90 days. Unmanaged = discovered, not assessed in 90 days. State ≠ Severity.

Flow 1 · five tools, one question each
Write host + IP + UTC first · then pick the tool Is Tenable scanning? five questions, not one Asset In inventory? Name · ID · Last Seen Explore → Assets Hosts · Managed / Unmanaged not a Plugin ID Last scan When assessed? Last Scan Time Auth vs Licensed Asset columns dates can split Scanner / agent Sensor alive? Status Online Last Connect Sensors → Linked not a finding Plugin / finding This Plugin ID? State · VPR First / Last Seen Explore → Findings not a host miss Scan job Job running? Status · % Warnings Scans → VM Scans not a VPR drop Empty Findings is data. It usually means the asset, the sensor, or the job never landed. Do not invent a patch job from an empty list. Start at Explore Assets or scan Status.

Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing.

Say this out loud

I prove the asset, then the last scan, then the scanner or agent, then the finding, then the job. I do not launch a VLAN-wide Advanced scan, unlink an agent, or recast a Plugin ID until I can quote the field that made me do it.

3. Decision flow — ticket → first tool

Flowchart first. Do not open Create a Scan until a diamond says so.

Path · pick the branch before the menu
Abstract diamond splitting into five Tenable proof paths with one amber break
Notice: the diamond is the ticket. The path is the tool. The field comes last. Do not reverse that order.
Flow 2 · first-tool diamond
Symptom first · tool second · field third What must we prove? Host in inventory? or already inside? Host missing Explore → Assets Name · Last Seen Host old / shallow Last Scan Time Auth vs Licensed Agent / scanner Sensors → Linked Status · Last Connect This plugin / empty Explore → Findings State · Plugin ID Is the job running? Scans → VM Scans Status · Warnings No asset record → stop. There is no Plugin ID to chase and no Last Scan Time to move. Fix targeting / network / discovery, then re-open Explore Assets. Do not Launch Scan on a missing asset. Diamond = decision. Do not Launch Scan from the bottom box. Managed = assessed in 90 days. Unmanaged = discovered, not assessed. Hover Status for targets + elapsed time.

Read the diamond first. A missing host never starts in Findings. A whole-VLAN miss never starts in one Plugin ID. “Is the job running?” never starts in VPR.

4. How to choose — first tool + proof field

Print this next to cloud.tenable.com. If you cannot recite the proof field, you are not ready to change anything.

If the ticket says…First tool (official path)Proof fieldDo not open first
Host missing / “is this box even in Tenable?” Explore → Assets → Hosts (also check Unmanaged Assets if Last Licensed Scan is older than 90 days) Asset Name + Asset ID + Last Seen + IPv4 Addresses — or the official empty result A new unauthenticated Advanced scan of the VLAN
Host exists; last scan looks weeks old / findings look too small Same asset details / columns: last-scan family Last Scan Time + Last Authenticated Scan + Last Licensed Scan + Last Scan Target Recast / Accept, a plugin disable
Agent installed yesterday; still no findings — or scanner “green” but VLAN empty Sensors → Nessus Agents → Linked Agents or Nessus Scanners → Linked Scanners Status (Online / Offline / Initializing) + Last Connect + Last Scanned + Health Explore Findings VPR sort
“This plugin is gone” / empty detections on a live host Explore → Findings → Vulnerabilities Plugin ID + State + VPR + First Seen / Last Seen / Last Fixed Scanner Hard restart
“Is the scan actually running?” / whole branch missed 02:00 Scans → Vulnerability Management Scans → that job → See All Details Status (Initializing / Running / Publishing Results / Completed / Pending / Aborted / Canceled) + Warnings + Scanner + Targets A new Recast so the PDF shrinks
Last Authenticated Scan vs Last Licensed Scan (official)

Tenable Asset Columns: an authenticated scan that only uses discovery plugins updates Last Authenticated Scan, but not Last Licensed Scan. An unauthenticated scan that runs non-discovery plugins updates Last Licensed Scan, but not Last Authenticated Scan. A licensed scan is what can identify vulnerabilities and count toward the license. Quote both timestamps. One fresh date is not “fully scanned.”

5. Runbook Side A → B → C

Side A proves the asset and the last scan. Side B proves the plugin / finding. Side C proves the scanner or agent and the scan job. On a messy Sev-2, do them in this order until a field lights up.

Side A — Asset record + last scan (inventory / assessment)

  1. Prove the host exists before you talk about Plugin ID

    Open Explore → Assets. Filter Hosts on hostname, IPv4 Addresses, or tag. Official: Asset Columns; View Asset Details. Quote Asset Name (Tenable builds it from Agent Name, local hostname, NetBIOS, DNS/FQDN, then IPv4/IPv6), Asset ID (the TVM UUID), Last Seen (last successful scan or import), Sources, Has Agent, Has Plugin Results. No row → stop. The IP was never observed, lives in another Network, or aged into a place your filter hides.

  2. If the weekly PDF is empty, also open Unmanaged Assets

    Official Asset Types: Managed Assets were assessed for vulnerabilities in the past 90 days. Unmanaged Assets were discovered by Tenable Vulnerability Management or Nessus but not scanned for vulnerabilities in the past 90 days. A host that “vanished” from Managed is often still there as Unmanaged — that is a last-scan ticket, not “Tenable deleted Finance.”

  3. Quote Last Scan Time, then split authenticated vs licensed

    On the same asset: Last Scan Time (last_scan_time), Last Authenticated Scan (last_authenticated_scan_time), Last Licensed Scan (last_licensed_scan_time), Last Scan Target (the IP or FQDN the last scan aimed at), Last Scan ID. Official: Asset Columns; Explore Assets export keys. If Last Licensed Scan is null or old while Last Authenticated Scan is fresh, last night may have been discovery-only. If Last Licensed Scan is fresh and Last Authenticated Scan is empty, you scanned the cover, not the book.

  4. Match Last Scan Target to the name they typed

    DHCP and dual-home hosts lie. Last Scan Target is the address the job used. If they searched the new IP and the record still keys on the old FQDN, you are looking at a merge / Tenable UUID problem — the factory’s ghost-asset trap — not a dead scanner.

cloud.tenable.com · Explore → Assets → Hosts
Training mock · not live

Explore / Assets / Hosts · filter

Assets

fin-app-41 or 203.0.113.41
Managed · Hosts
Asset NameIPv4Last SeenLast Auth ScanLast Licensed ScanHas Agent
fin-app-41.lab.example203.0.113.4116 min2026-08-15 02:11Z2026-08-15 02:11ZYes
lab-build-09.lab.example203.0.113.1918 days2026-07-28No

Source: Tenable Docs — Asset Columns (Asset Name, Last Seen, Last Authenticated Scan, Last Licensed Scan); Explore Assets Export Fields (last_scan_time, last_authenticated_scan_time, last_licensed_scan_time, has_agent). Lab identities and RFC 5737 IPs only. Training mock · not live.

Side B — Plugin / finding (what the engine said)

  1. Open Findings, not Recast

    Path: Explore → Findings → Vulnerabilities. Official: Findings Columns; View Findings Details; Vulnerability States. Filter Asset Name + Plugin ID + time. A WAS finding is a different finding type — do not close a host OpenSSL ticket from Web Application Findings.

  2. Read State, then Plugin ID, then VPR

    State is New (seen once), Active (seen more than once; the Active filter also returns New), Fixed (previously seen, no longer detected — use Last Fixed), or Resurfaced (was Fixed, seen again). Plugin ID + Plugin Name name the check. VPR is 0.1–10. Severity is the CVSS-based column — the factory already taught you not to sort the night on Severity alone.

  3. If the row is empty, that is a Side A or Side C ticket

    Empty Findings with a missing asset is inventory. Empty Findings with a stale Last Licensed Scan is assessment. Empty Findings with Status = Aborted is the job. Official Scans note: an asset that only received inventory scanning continues to report old vulnerabilities until it ages out, even if it is offline. Stale Active is not “still exploitable tonight” until Last Seen is fresh.

Explore Findings — fields you write in the ticket
Path:            Explore → Findings → Vulnerabilities
Asset:           fin-app-41.lab.example   Asset ID = TVM UUID
Plugin ID:       156999   (lab)
Quote:           State + Plugin ID + VPR + First Seen / Last Seen
If Fixed:        Last Fixed
If empty list:   Last Licensed Scan / Linked Agent Status / scan Status

Side C — Scanner / agent health + scan job status

  1. If they said “we installed the agent,” open Linked Agents — not Findings

    Path: left nav Sensors (default tab is Nessus Scanners / Linked Scanners) → Nessus AgentsLinked Agents. Official: Manage Linked Agents; Agent Status; View Sensors. After install the agent should appear once it links. No row means it never presented the linking key to this container.

  2. Read Status, then Last Connect, then Last Scanned, then Health

    Status: Online = the host is connected and talking to Tenable Vulnerability Management. Offline = powered down or not on a network — in TVM the Offline badge appears after the agent has not connected for two hours. Initializing = checking in. Export columns: Last Connect (last check-in, ISO-8601), Last Scanned, Last Plugin Update. Official Agents: linked agents check in on start, after a restart, and when metadata updates (no more than every 10 minutes). Health: Healthy / Warning / Critical / Unknown. Overall Health: Safe Mode (agent ≥ 10.9.0) means it cannot compile plugins or run scans, but it stays connected so you can recover it — that is not “Online means scanning.”

  3. If the whole VLAN missed 02:00, open the scanner and the job

    Same Sensors page, Nessus Scanners → Linked Scanners. Quote scanner Status (Online / Offline), Last Scanned, Scans (jobs currently running), Plugin Set, Network. Official Error Messages: Inactive Scanners and Routed To Inactive Scanners mean the scanner group has no active scanner — confirm the group, then re-run. Then open Scans → Vulnerability Management Scans, click the job, See All Details.

  4. Read scan Status the way Tenable defines it — not the way Slack uses “running”

    Official typical flow: Initializing → Running → Publishing Results → Completed. Hover Status for targets scanned and elapsed / final time. Pending = queued, assigning tasks to sensors — Tenable aborts scans that stay Pending more than four hours (overlap / schedule). Running shows a percent of completed scan tasks (a job under 120 IPs is one task, so the bar jumps 0 → 100). Publishing Results starts when Running hits 100%. Aborted = scanner/platform problems, or queued ≥ four hours — open the Warnings tab (and Download All Warnings JSON). Canceled is a user stop. Paused more than 14 days times out to Aborted. Empty = new or not yet run. History: Start Time, End Time, Duration, Status. Individual scan details keep 35 days of plugin/asset tabs; scan data is retained 15 months.

cloud.tenable.com · Sensors → Nessus Agents → Linked Agents
Training mock · not live

Sensors / Nessus Agents / Linked Agents / fin-app-41

Linked agent

Online
2026-08-16T01:28:00Z
2026-08-15T02:11:00Z
Healthy
OFFLINE LINE (the other outcome):
Status = Offline · Last Connect older than 2 hours
Initializing = checking in · Safe Mode = cannot compile plugins or run scans.

Source: Tenable Docs — Manage Linked Agents (Last Connect, Last Scanned, Status online/offline/unlinked); Agent Status (Online, Offline after two hours, Initializing); View Sensors (Health, Last Plugin Update); Agent Safe Mode. Lab agent name only.

cloud.tenable.com · Scans → Vulnerability Management Scans → Weekly-Pune-Adv
Training mock · not live

Scans / Vulnerability Management Scans / Weekly-Pune-Adv / See All Details

Scan details

Completed
Advanced Network Scan
Pune-Nessus-01
2026-08-15 02:00Z
PENDING / ABORT LINE (the other outcome):
Status = Pending · queued > 4 hours → Aborted
Warnings: Inactive Scanners · Routed To Inactive Scanners

Source: Tenable Docs — Scan Status (Initializing, Running, Publishing Results, Completed, Pending 4-hour abort, Aborted, Canceled, Paused 14-day timeout); Scan Details (Status, Start Time, Template, Scanner, Targets, Warnings, History). Lab scan name only.

Green success on each side

6. Five tickets as full stories

These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only (RFC 5737 addresses, example.com names).

Journey · one amber last-scan is the ticket
Operations desk with abstract green health checks and one highlighted last-scan field
Notice: Explore can still list the host while Last Licensed Scan is eighteen days old. That is a last-scan ticket, not a Plugin ID ticket.
TicketSymptomFirst toolProof field
TENED-01Finance box missing from the weekly; “is Tenable even scanning?”Explore → AssetsAsset row — or official empty search
TENED-02Host in inventory; last scan 18 days / findings look thinAsset last-scan columnsLast Scan Time + Last Authenticated Scan + Last Licensed Scan
TENED-03Agent installed last night; still no findingsSensors → Linked AgentsStatus + Last Connect + Last Scanned + Health
TENED-04CISO: “plugin 156999 is gone”; weekly still lists itExplore → FindingsState + Plugin ID + VPR + Last Seen / Last Fixed
TENED-05Whole Pune VLAN missed 02:00; “is the scan actually running?”Scans → VM Scans + Linked ScannersJob Status + Warnings + scanner Status

TENED-01 — Prove the asset (Explore → Assets)

01:42 · P2. Priya: the Finance box is not on the weekly. L1 already queued an unauthenticated Advanced scan of 203.0.113.0/24.

First tool: Explore → Assets → Hosts. Search fin-app-41 and 203.0.113.41. If Managed is empty, switch to Unmanaged Assets (not assessed in 90 days).

If empty on both: the host was never observed in this Network / container. Quote the empty result. Next check is discovery targets, Network assignment, or a linking-key agent that never checked in — not a new scan template. Official: assets appear when a scanner, agent, import, or connector identifies them.

If present: quote Asset Name, Asset ID, IPv4, Last Seen, Sources, Has Agent. Now you are allowed to ask about Last Licensed Scan. The asset card is not a Plugin ID.

Trap

Do not trust a colleague’s Explore search from a different access group. Scan-level “Can View” is not the same as aggregated Explore access (official Scan Details note). Dual-home / DHCP: search Last Scan Target as well as the IP they typed tonight.

TENED-02 — Prove the last scan (auth vs licensed)

02:20 · P2. Host exists. Last Seen is this week. Findings look suspiciously small. Security thinks Tenable stopped.

First tool: the same asset details. Read the three clocks.

Proof field: Last Scan Time + Last Authenticated Scan + Last Licensed Scan + Last Scan Target. If Last Authenticated Scan is last night and Last Licensed Scan is 18 days old, last night was discovery-only — official: discovery-plugin auth updates Last Authenticated Scan only. If Last Licensed Scan is last night and Last Authenticated Scan is empty, the job finished unauthenticated — completed ≠ authenticated (factory stamp two). Quote Last Scan ID if you need the exact job on the Scans page.

Close

I would not declare a platform outage from one stale clock. I would paste both last-scan fields and say whether last night was licensed, authenticated, or only discovery. Unlocking the scan account is change-control, not isolate.

TENED-03 — Prove the agent (Linked Agents)

02:05 · P2. Imaging dropped the Tenable Agent at 18:00. Findings are still empty. Someone wants the installer re-pushed.

First tool: Sensors → Nessus Agents → Linked Agents. Filter the hostname.

Proof field: no row → never linked (linking key / outbound to Tenable / wrong container). Status = Initializing and Last Connect is minutes → it is checking in; wait. Status = Online, Last Connect minutes, Last Scanned empty → linked but no agent scan job has finished — that is a scan configuration / agent group ticket, not an MSI ticket. Status = Offline and Last Connect older than two hours → the host is not talking; re-push will not help until the box is up and can check in. Health = Safe Mode → quote Overall Health: Safe Mode; recover the agent (it cannot compile plugins or run scans).

Close

I would not re-push. I would quote Status + Last Connect + Last Scanned. Re-push is change-control when the agent already linked. Official: Offline agents keep trying connectivity about every 30 minutes; triggered scans can still run offline and upload later.

TENED-04 — Prove the finding (Explore → Findings)

02:40 · P2. CISO: “Plugin 156999 is gone.” The weekly PDF still lists it. L1 wants the plugin disabled.

First tool: Explore → Findings. Filter host + Plugin ID 156999 (lab).

Proof field: State + Plugin ID + VPR + Last Seen. Active + Last Seen last night → it is not gone. Fixed + Last Fixed today → the weekly is stale. Resurfaced → it was Fixed and came back; that is a patch-regressed ticket, not a new CVE until the plugin says so. Empty row with a fresh Last Licensed Scan → the finding is not on this Asset ID; do not disable the plugin globally to clean a PDF.

Trap

WAS findings live under Web Application Findings, not this host Plugin ID. Recast / Accept changes visible severity or hides the finding — it does not rewrite the raw scan (factory Side C). Quote State on the live Asset ID, not the PDF cover.

TENED-05 — Prove the job is running (scan Status + scanner)

03:00 · P1. Pune VLAN: every desk missed the 02:00 scan. Findings for that tag are empty. L1 wants a force launch of every Advanced scan in the folder.

First tool: Scans → Vulnerability Management Scans for Weekly-Pune-Adv, then Sensors → Nessus Scanners → Linked Scanners for Pune-Nessus-01.

Proof field: job Status + Warnings + scanner Status. Pending since 02:00 and it is now 03:00 — still legal (four-hour abort has not fired); do not stack a second launch. Pending past four hours → official Aborted; reduce overlapping scans. Running 0% with one task (< 120 IPs) can sit at 0 until the single task finishes — that is not “stuck.” Status = Completed and Findings empty → the job finished; go back to targeting / auth / Last Scan Target, not another launch. Scanner Offline + Warnings “Inactive Scanners” / “Routed To Inactive Scanners” → restore the sensor, then re-run. Simultaneous VLAN silence is almost never “every Plugin ID Fixed at once.”

Close

I would leave Recast alone. I would paste job Status, the Warnings line, and scanner Status. A second unauthenticated /24 is change-control, not isolate. Hover Status for targets + elapsed time before you say the job is dead.

7. Traps + close-the-ticket proof

You seeWeak closeStrong close
Empty Explore Assets (Managed)“Tenable is down” / scan the /24Check Unmanaged (90-day rule); quote empty or the Asset ID
Host present, still “missing”“Inventory is fine”You only proved the record. Open Last Licensed Scan / agent next
Last Authenticated Scan fresh, Last Licensed Scan old“We scanned last night”Official: discovery-only auth does not update Last Licensed Scan
Last Licensed Scan fresh, Last Authenticated Scan empty“We are safe”Unauthenticated licensed scan. Factory stamp two
No Linked Agent row after installRe-push the MSINever linked. Prove linking key / outbound / container
Agent OfflineSev-1 platformOfficial: Offline after two hours without connect. Quote Last Connect
Health = Safe Mode“Online, so it scanned”Cannot compile plugins or run scans. Recover the agent
Empty Findings on a live hostDisable the pluginLast Licensed Scan + agent Status + job Status first
State = Fixed, weekly still lists itNew criticalQuote Last Fixed. The PDF is stale
Scan Status = PendingLaunch it againQueued. Four-hour abort if it stays there. Check overlap
Running 0% on a small jobAbort and rerunOfficial: < 120 IPs = one task; bar jumps 0 → 100
Scanner Online, VLAN quietHard-restart NessusTargets, Network, Warnings, Last Scan Target
Completed job, old vulns remain“Scan failed”Official: inventory-only assets keep reporting until they age out
Proof checklist before you leave the bridge
Interview close

I name the question, then the first tool, then one official field. Explore Assets proves the host. Last Authenticated Scan vs Last Licensed Scan proves the assessment. Sensors Last Connect proves the scanner or agent. Findings State + Plugin ID proves the result. Scan Status proves the job. I do not launch a /24, re-push an agent, or disable a plugin until that field is on the ticket. Factory model: completed ≠ authenticated ≠ exploitable.

Knowledge check

Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

Q1

Weekly PDF is missing the Finance box. Slack: “Is Tenable even scanning?” You have not opened Findings yet. First proof?

Correct: b. Official Explore Assets inventory. No row means there is no Last Scan Time and no Plugin ID to hunt. Re-read Side A step 1 and TENED-01.
Q2

Last Authenticated Scan is last night. Last Licensed Scan is 18 days old. Findings look thin. What is that pair allowed to mean?

Correct: a. Official Asset Columns caveat. The inverse (licensed unauth, no Last Authenticated Scan) is the factory’s failed-auth week. Re-read the callout and TENED-02.
Q3

Imaging installed the Tenable Agent at 18:00. Findings are still empty at 02:00. Which proof field closes TENED-03 first?

Correct: c. Official Agent Status and Linked Agent export fields. No row = not linked. Offline appears after two hours. Safe Mode cannot scan. WAS is a different object. Re-read Side C steps 1–2 and TENED-03.
Q4

CISO says plugin 156999 is gone. The weekly still lists it on fin-app-41. First tool + proof?

Correct: b. Official Findings Columns and Vulnerability States (New / Active / Fixed / Resurfaced). Re-read Side B and TENED-04.
Q5

Pune VLAN missed the 02:00 job. Slack: “Is the scan actually running?” What do you open first?

Correct: d. Official Scan Status (Pending is not Running; four-hour abort) and scanner Inactive / Routed errors. Re-read Side C steps 3–4 and TENED-05.
Q6

The 02:00 job still shows Status = Pending at 03:10. What is that sentence allowed to mean?

Correct: a. Official Scan Status: Pending = queued; abort after four hours. Hover Status for targets + elapsed time. Re-read Side C step 4 and TENED-05.

Sources

Related: Blog 1 · Tenable session factory — completed ≠ authenticated ≠ exploitable · Tenable interview hub · VPR prioritization · Nessus scanning · WAS lesson