# Prove Tenable is scanning — first tool + proof field

Source: https://ai.techclick.in/blog_tenable_evidence_desk
Markdown: https://ai.techclick.in/blog_tenable_evidence_desk.md
Publisher: Techclick Infosec Pvt Ltd

How you prove Tenable is scanning: Explore asset, last scan, scanner/agent health, plugin finding, scan job status. Five tickets with first tool and one proof field.

Quick answer (say this out loud)

    Explore → Assets  answers “is this host even in the container?”  Last Scan Time / Last Authenticated Scan / Last Licensed Scan  answers “when did an assessment last land — and was it credentialed?”  Sensors  answers “is the Nessus scanner or Tenable Agent that should have hit this host Online, and when did it last connect?”  Explore → Findings  answers “is this Plugin ID New, Active, Fixed, or Resurfaced — and what is VPR?”  Scans → Vulnerability Management Scans  answers “is the job Initializing, Running, Publishing Results, Completed, Pending, or Aborted?” A green dashboard tile is not a host record. An empty weekly PDF is not a dead platform.

## 1. Why “is it scanning?” is five questions

 Operators collapse five failures into one sentence. The IP was never observed as an asset. The last licensed scan is eighteen days old. The Pune Nessus scanner is Offline. Plugin 156999 is Fixed on this Asset ID but still on the PDF. The 02:00 job sat in Pending until Tenable aborted it at four hours. Those are five first clicks.

 This page is the night-shift desk for  proof . The factory taught completed ≠ authenticated ≠ exploitable. Here you learn the five tools you actually open, in order, when someone asks you to prove Tenable Vulnerability Management / Nessus is scanning — or to explain why a host is missing.

   Hero · five tiles, one missing host

   Notice: five tiles, not one “Tenable dashboard.” You pick the tile that matches the question, then you quote one field.

   Interview line

   If they say “prove Tenable is scanning,” do not say “I opened Explore.” Say: “I prove the host in Explore Assets with  Asset Name  +  Last Seen , the assessment with  Last Authenticated Scan  vs  Last Licensed Scan , the sensor with  Status  +  Last Connect , the finding with  Plugin ID  +  State , and the job with scan  Status .”

## 2. Mental model — five proof tools

 Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you launch a second scan of a box that was never in the target list.

#### 1 · Asset

      Explore → Assets  (Hosts). Proves the record:  Asset Name ,  Asset ID ,  IPv4 Addresses ,  Last Seen ,  Sources ,  Has Agent . Does not prove last licensed scan or a Plugin ID.

#### 2 · Last scan

     Same asset pane / columns:  Last Scan Time ,  Last Authenticated Scan ,  Last Licensed Scan ,  Last Scan Target ,  Last Scan ID . Proves when an assessment last landed — and whether credentials or only discovery ran.

#### 3 · Scanner / agent

      Sensors → Nessus Scanners  (Linked Scanners) or  Nessus Agents → Linked Agents . Proves sensor life:  Status  (Online / Offline),  Last Connect ,  Last Scanned ,  Health . Online ≠ it reached the subnet.

#### 4 · Plugin / finding

      Explore → Findings  (Vulnerabilities). Proves one result:  Plugin ID  +  State  (New / Active / Fixed / Resurfaced) +  VPR  +  Severity  +  First Seen . Empty list is data.

#### 5 · Scan job

      Scans → Vulnerability Management Scans . Proves the job:  Status  (Initializing → Running → Publishing Results → Completed), plus  Scanner ,  Targets ,  Warnings . Pending is not Running.

#### Hard words, once

      Last Licensed Scan  = last scan with non-discovery plugins (counts toward license).  Managed  = assessed in 90 days.  Unmanaged  = discovered, not assessed in 90 days.  State ≠ Severity .

   Flow 1 · five tools, one question each

       Five proof tools and the one question each is allowed to answer

- Write host + IP + UTC first · then pick the tool Is Tenable scanning? five questions, not one Asset In inventory? Name · ID · Last Seen Explore → Assets Hosts · Managed / Unmanaged not a Plugin ID Last scan When assessed? Last Scan Time Auth vs Licensed Asset columns dates can split Scanner / agent Sensor alive? Status Online Last Connect Sensors → Linked not a finding Plugin / finding This Plugin ID? State · VPR First / Last Seen Explore → Findings not a host miss Scan job Job running? Status · % Warnings Scans → VM Scans not a VPR drop Empty Findings is data. It usually means the asset, the sensor, or the job never landed. Do not invent a patch job from an empty list. Start at Explore Assets or scan Status. Read left → right. Each box is allowed one claim. If you cannot name the field, you are not proving — you are guessing. Say this out loud I prove the asset, then the last scan, then the scanner or agent, then the finding, then the job. I do not launch a VLAN-wide Advanced scan, unlink an agent, or recast a Plugin ID until I can quote the field that made me do it. ## 3. Decision flow — ticket → first tool Flowchart first. Do not open Create a Scan until a diamond says so. Path · pick the branch before the menu Notice: the diamond is the ticket. The path is the tool. The field comes last. Do not reverse that order. Flow 2 · first-tool diamond Decision diamond from symptom to first proof tool Symptom first · tool second · field third What must we prove? Host in inventory? or already inside? Host missing Explore → Assets Name · Last Seen Host old / shallow Last Scan Time Auth vs Licensed Agent / scanner Sensors → Linked Status · Last Connect This plugin / empty Explore → Findings State · Plugin ID Is the job running? Scans → VM Scans Status · Warnings No asset record → stop. There is no Plugin ID to chase and no Last Scan Time to move. Fix targeting / network / discovery, then re-open Explore Assets. Do not Launch Scan on a missing asset. Diamond = decision. Do not Launch Scan from the bottom box. Managed = assessed in 90 days. Unmanaged = discovered, not assessed. Hover Status for targets + elapsed time. Read the diamond first. A missing host never starts in Findings. A whole-VLAN miss never starts in one Plugin ID. “Is the job running?” never starts in VPR. ## 4. How to choose — first tool + proof field Print this next to cloud.tenable.com. If you cannot recite the proof field, you are not ready to change anything. If the ticket says… First tool (official path) Proof field Do not open first Host missing / “is this box even in Tenable?” Explore → Assets → Hosts (also check Unmanaged Assets if Last Licensed Scan is older than 90 days) Asset Name + Asset ID + Last Seen + IPv4 Addresses — or the official empty result A new unauthenticated Advanced scan of the VLAN Host exists; last scan looks weeks old / findings look too small Same asset details / columns: last-scan family Last Scan Time + Last Authenticated Scan + Last Licensed Scan + Last Scan Target Recast / Accept, a plugin disable Agent installed yesterday; still no findings — or scanner “green” but VLAN empty Sensors → Nessus Agents → Linked Agents or Nessus Scanners → Linked Scanners Status (Online / Offline / Initializing) + Last Connect + Last Scanned + Health Explore Findings VPR sort “This plugin is gone” / empty detections on a live host Explore → Findings → Vulnerabilities Plugin ID + State + VPR + First Seen / Last Seen / Last Fixed Scanner Hard restart “Is the scan actually running?” / whole branch missed 02:00 Scans → Vulnerability Management Scans → that job → See All Details Status (Initializing / Running / Publishing Results / Completed / Pending / Aborted / Canceled) + Warnings + Scanner + Targets A new Recast so the PDF shrinks Last Authenticated Scan vs Last Licensed Scan (official) Tenable Asset Columns: an authenticated scan that only uses discovery plugins updates Last Authenticated Scan , but not Last Licensed Scan . An unauthenticated scan that runs non-discovery plugins updates Last Licensed Scan , but not Last Authenticated Scan . A licensed scan is what can identify vulnerabilities and count toward the license. Quote both timestamps. One fresh date is not “fully scanned.” ## 5. Runbook Side A → B → C Side A proves the asset and the last scan. Side B proves the plugin / finding. Side C proves the scanner or agent and the scan job. On a messy Sev-2, do them in this order until a field lights up. ### Side A — Asset record + last scan (inventory / assessment) #### Prove the host exists before you talk about Plugin ID Open Explore → Assets . Filter Hosts on hostname, IPv4 Addresses , or tag. Official: Asset Columns; View Asset Details. Quote Asset Name (Tenable builds it from Agent Name, local hostname, NetBIOS, DNS/FQDN, then IPv4/IPv6), Asset ID (the TVM UUID), Last Seen (last successful scan or import), Sources , Has Agent , Has Plugin Results . No row → stop. The IP was never observed, lives in another Network, or aged into a place your filter hides.

- #### If the weekly PDF is empty, also open Unmanaged Assets Official Asset Types: Managed Assets were assessed for vulnerabilities in the past 90 days. Unmanaged Assets were discovered by Tenable Vulnerability Management or Nessus but not scanned for vulnerabilities in the past 90 days. A host that “vanished” from Managed is often still there as Unmanaged — that is a last-scan ticket, not “Tenable deleted Finance.”

- #### Quote Last Scan Time, then split authenticated vs licensed On the same asset: Last Scan Time ( last_scan_time ), Last Authenticated Scan ( last_authenticated_scan_time ), Last Licensed Scan ( last_licensed_scan_time ), Last Scan Target (the IP or FQDN the last scan aimed at), Last Scan ID . Official: Asset Columns; Explore Assets export keys. If Last Licensed Scan is null or old while Last Authenticated Scan is fresh, last night may have been discovery-only. If Last Licensed Scan is fresh and Last Authenticated Scan is empty, you scanned the cover, not the book.

- #### Match Last Scan Target to the name they typed DHCP and dual-home hosts lie. Last Scan Target is the address the job used. If they searched the new IP and the record still keys on the old FQDN, you are looking at a merge / Tenable UUID problem — the factory’s ghost-asset trap — not a dead scanner.

     cloud.tenable.com · Explore → Assets → Hosts

     Training mock · not live

       Explore / Assets / Hosts · filter

### Assets

          Query  fin-app-41 or 203.0.113.41

          Type  Managed · Hosts

           Asset Name  IPv4  Last Seen  Last Auth Scan  Last Licensed Scan  Has Agent

            fin-app-41.lab.example  203.0.113.41  16 min  2026-08-15 02:11Z  2026-08-15 02:11Z   Yes
            lab-build-09.lab.example  203.0.113.19  18 days  —  2026-07-28   No

        Reset  Apply

    Source:  Tenable Docs — Asset Columns ( Asset Name ,  Last Seen ,  Last Authenticated Scan ,  Last Licensed Scan ); Explore Assets Export Fields ( last_scan_time ,  last_authenticated_scan_time ,  last_licensed_scan_time ,  has_agent ). Lab identities and RFC 5737 IPs only. Training mock · not live.

### Side B — Plugin / finding (what the engine said)

- #### Open Findings, not Recast Path: Explore → Findings → Vulnerabilities. Official: Findings Columns; View Findings Details; Vulnerability States. Filter Asset Name + Plugin ID + time. A WAS finding is a different finding type — do not close a host OpenSSL ticket from Web Application Findings.

- #### Read State, then Plugin ID, then VPR State is New (seen once), Active (seen more than once; the Active filter also returns New), Fixed (previously seen, no longer detected — use Last Fixed ), or Resurfaced (was Fixed, seen again). Plugin ID + Plugin Name name the check. VPR is 0.1–10. Severity is the CVSS-based column — the factory already taught you not to sort the night on Severity alone.

- #### If the row is empty, that is a Side A or Side C ticket Empty Findings with a missing asset is inventory. Empty Findings with a stale Last Licensed Scan is assessment. Empty Findings with Status = Aborted is the job. Official Scans note: an asset that only received inventory scanning continues to report old vulnerabilities until it ages out, even if it is offline. Stale Active is not “still exploitable tonight” until Last Seen is fresh.

  Explore Findings — fields you write in the ticket  Path:            Explore → Findings → Vulnerabilities
Asset:           fin-app-41.lab.example   Asset ID = TVM UUID
Plugin ID:       156999   (lab)
Quote:           State + Plugin ID + VPR + First Seen / Last Seen
If Fixed:        Last Fixed
If empty list:   Last Licensed Scan / Linked Agent Status / scan Status

### Side C — Scanner / agent health + scan job status

- #### If they said “we installed the agent,” open Linked Agents — not Findings Path: left nav Sensors (default tab is Nessus Scanners / Linked Scanners) → Nessus Agents → Linked Agents . Official: Manage Linked Agents; Agent Status; View Sensors. After install the agent should appear once it links. No row means it never presented the linking key to this container.

- #### Read Status, then Last Connect, then Last Scanned, then Health Status : Online = the host is connected and talking to Tenable Vulnerability Management. Offline = powered down or not on a network — in TVM the Offline badge appears after the agent has not connected for two hours . Initializing = checking in. Export columns: Last Connect (last check-in, ISO-8601), Last Scanned , Last Plugin Update . Official Agents: linked agents check in on start, after a restart, and when metadata updates (no more than every 10 minutes). Health : Healthy / Warning / Critical / Unknown. Overall Health: Safe Mode (agent ≥ 10.9.0) means it cannot compile plugins or run scans, but it stays connected so you can recover it — that is not “Online means scanning.”

- #### If the whole VLAN missed 02:00, open the scanner and the job Same Sensors page, Nessus Scanners → Linked Scanners . Quote scanner Status (Online / Offline), Last Scanned , Scans (jobs currently running), Plugin Set , Network. Official Error Messages: Inactive Scanners and Routed To Inactive Scanners mean the scanner group has no active scanner — confirm the group, then re-run. Then open Scans → Vulnerability Management Scans , click the job, See All Details .

- #### Read scan Status the way Tenable defines it — not the way Slack uses “running” Official typical flow: Initializing → Running → Publishing Results → Completed . Hover Status for targets scanned and elapsed / final time. Pending = queued, assigning tasks to sensors — Tenable aborts scans that stay Pending more than four hours (overlap / schedule). Running shows a percent of completed scan tasks (a job under 120 IPs is one task, so the bar jumps 0 → 100). Publishing Results starts when Running hits 100%. Aborted = scanner/platform problems, or queued ≥ four hours — open the Warnings tab (and Download All Warnings JSON). Canceled is a user stop. Paused more than 14 days times out to Aborted. Empty = new or not yet run. History: Start Time , End Time , Duration , Status . Individual scan details keep 35 days of plugin/asset tabs; scan data is retained 15 months.

     cloud.tenable.com · Sensors → Nessus Agents → Linked Agents

     Training mock · not live

       Sensors / Nessus Agents / Linked Agents / fin-app-41

### Linked agent

          Status  Online

          Last Connect  2026-08-16T01:28:00Z

          Last Scanned  2026-08-15T02:11:00Z

          Health  Healthy

OFFLINE LINE (the other outcome):

 Status = Offline · Last Connect older than 2 hours

Initializing = checking in · Safe Mode = cannot compile plugins or run scans.

    Source:  Tenable Docs — Manage Linked Agents (Last Connect, Last Scanned, Status online/offline/unlinked); Agent Status (Online, Offline after two hours, Initializing); View Sensors (Health, Last Plugin Update); Agent Safe Mode. Lab agent name only.

     cloud.tenable.com · Scans → Vulnerability Management Scans → Weekly-Pune-Adv

     Training mock · not live

       Scans / Vulnerability Management Scans / Weekly-Pune-Adv / See All Details

### Scan details

          Status  Completed

          Template  Advanced Network Scan

          Scanner  Pune-Nessus-01

          Start Time  2026-08-15 02:00Z

PENDING / ABORT LINE (the other outcome):

 Status = Pending · queued &gt; 4 hours → Aborted

 Warnings: Inactive Scanners · Routed To Inactive Scanners

        History  See All Details

    Source:  Tenable Docs — Scan Status (Initializing, Running, Publishing Results, Completed, Pending 4-hour abort, Aborted, Canceled, Paused 14-day timeout); Scan Details (Status, Start Time, Template, Scanner, Targets, Warnings, History). Lab scan name only.

   Green success on each side

- Side A asset: Explore Assets returns Asset Name + Asset ID + Last Seen. Side A last scan: Last Scan Time plus both Last Authenticated Scan and Last Licensed Scan, or you can name why they differ.

- Side B: Findings quotes Plugin ID + State + VPR (and Last Fixed if State is Fixed).

- Side C sensor: Linked Agents / Linked Scanners shows Status and Last Connect for the sensor that owns the host.

- Side C job: scan Status is Running (with %) or Completed — not Pending mistaken for Running — and Warnings is empty or quoted.

## 6. Five tickets as full stories

 These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only (RFC 5737 addresses, example.com names).

   Journey · one amber last-scan is the ticket

   Notice: Explore can still list the host while Last Licensed Scan is eighteen days old. That is a last-scan ticket, not a Plugin ID ticket.

     Ticket  Symptom  First tool  Proof field

       TENED-01   Finance box missing from the weekly; “is Tenable even scanning?”  Explore → Assets  Asset row — or official empty search
       TENED-02   Host in inventory; last scan 18 days / findings look thin  Asset last-scan columns  Last Scan Time + Last Authenticated Scan + Last Licensed Scan
       TENED-03   Agent installed last night; still no findings  Sensors → Linked Agents  Status + Last Connect + Last Scanned + Health
       TENED-04   CISO: “plugin 156999 is gone”; weekly still lists it  Explore → Findings  State + Plugin ID + VPR + Last Seen / Last Fixed
       TENED-05   Whole Pune VLAN missed 02:00; “is the scan actually running?”  Scans → VM Scans + Linked Scanners  Job Status + Warnings + scanner Status

### TENED-01 — Prove the asset (Explore → Assets)

  01:42 · P2.  Priya: the Finance box is not on the weekly. L1 already queued an unauthenticated Advanced scan of 203.0.113.0/24.

  First tool:   Explore → Assets  → Hosts. Search  fin-app-41  and  203.0.113.41 . If Managed is empty, switch to  Unmanaged Assets  (not assessed in 90 days).

  If empty on both:  the host was never observed in this Network / container. Quote the empty result. Next check is discovery targets, Network assignment, or a linking-key agent that never checked in — not a new scan template. Official: assets appear when a scanner, agent, import, or connector identifies them.

  If present:  quote Asset Name, Asset ID, IPv4, Last Seen, Sources, Has Agent. Now you are allowed to ask about Last Licensed Scan. The asset card is not a Plugin ID.

  Trap

 Do not trust a colleague’s Explore search from a different access group. Scan-level “Can View” is not the same as aggregated Explore access (official Scan Details note). Dual-home / DHCP: search Last Scan Target as well as the IP they typed tonight.

### TENED-02 — Prove the last scan (auth vs licensed)

  02:20 · P2.  Host exists. Last Seen is this week. Findings look suspiciously small. Security thinks Tenable stopped.

  First tool:  the same asset details. Read the three clocks.

  Proof field:   Last Scan Time  +  Last Authenticated Scan  +  Last Licensed Scan  +  Last Scan Target . If Last Authenticated Scan is last night and Last Licensed Scan is 18 days old, last night was discovery-only — official: discovery-plugin auth updates Last Authenticated Scan only. If Last Licensed Scan is last night and Last Authenticated Scan is empty, the job finished unauthenticated — completed ≠ authenticated (factory stamp two). Quote Last Scan ID if you need the exact job on the Scans page.

  Close

 I would not declare a platform outage from one stale clock. I would paste both last-scan fields and say whether last night was licensed, authenticated, or only discovery. Unlocking the scan account is change-control, not isolate.

### TENED-03 — Prove the agent (Linked Agents)

  02:05 · P2.  Imaging dropped the Tenable Agent at 18:00. Findings are still empty. Someone wants the installer re-pushed.

  First tool:   Sensors → Nessus Agents → Linked Agents . Filter the hostname.

  Proof field:  no row → never linked (linking key / outbound to Tenable / wrong container). Status = Initializing and Last Connect is minutes → it is checking in; wait. Status = Online, Last Connect minutes, Last Scanned empty → linked but no agent scan job has finished — that is a scan configuration / agent group ticket, not an MSI ticket. Status = Offline and Last Connect older than two hours → the host is not talking; re-push will not help until the box is up and can check in. Health = Safe Mode → quote Overall Health: Safe Mode; recover the agent (it cannot compile plugins or run scans).

  Close

 I would not re-push. I would quote Status + Last Connect + Last Scanned. Re-push is change-control when the agent already linked. Official: Offline agents keep trying connectivity about every 30 minutes; triggered scans can still run offline and upload later.

### TENED-04 — Prove the finding (Explore → Findings)

  02:40 · P2.  CISO: “Plugin 156999 is gone.” The weekly PDF still lists it. L1 wants the plugin disabled.

  First tool:   Explore → Findings . Filter host + Plugin ID 156999 (lab).

  Proof field:   State  +  Plugin ID  +  VPR  +  Last Seen . Active + Last Seen last night → it is not gone. Fixed + Last Fixed today → the weekly is stale. Resurfaced → it was Fixed and came back; that is a patch-regressed ticket, not a new CVE until the plugin says so. Empty row with a fresh Last Licensed Scan → the finding is not on this Asset ID; do not disable the plugin globally to clean a PDF.

  Trap

 WAS findings live under Web Application Findings, not this host Plugin ID. Recast / Accept changes visible severity or hides the finding — it does not rewrite the raw scan (factory Side C). Quote State on the live Asset ID, not the PDF cover.

### TENED-05 — Prove the job is running (scan Status + scanner)

  03:00 · P1.  Pune VLAN: every desk missed the 02:00 scan. Findings for that tag are empty. L1 wants a force launch of every Advanced scan in the folder.

  First tool:   Scans → Vulnerability Management Scans  for Weekly-Pune-Adv, then  Sensors → Nessus Scanners → Linked Scanners  for Pune-Nessus-01.

  Proof field:  job  Status  + Warnings + scanner  Status . Pending since 02:00 and it is now 03:00 — still legal (four-hour abort has not fired); do not stack a second launch. Pending past four hours → official Aborted; reduce overlapping scans. Running 0% with one task (&lt; 120 IPs) can sit at 0 until the single task finishes — that is not “stuck.” Status = Completed and Findings empty → the job finished; go back to targeting / auth / Last Scan Target, not another launch. Scanner Offline + Warnings “Inactive Scanners” / “Routed To Inactive Scanners” → restore the sensor, then re-run. Simultaneous VLAN silence is almost never “every Plugin ID Fixed at once.”

  Close

 I would leave Recast alone. I would paste job Status, the Warnings line, and scanner Status. A second unauthenticated /24 is change-control, not isolate. Hover Status for targets + elapsed time before you say the job is dead.

## 7. Traps + close-the-ticket proof

     You see  Weak close  Strong close

      Empty Explore Assets (Managed)  “Tenable is down” / scan the /24  Check Unmanaged (90-day rule); quote empty or the Asset ID
      Host present, still “missing”  “Inventory is fine”  You only proved the record. Open Last Licensed Scan / agent next
      Last Authenticated Scan fresh, Last Licensed Scan old  “We scanned last night”  Official: discovery-only auth does not update Last Licensed Scan
      Last Licensed Scan fresh, Last Authenticated Scan empty  “We are safe”  Unauthenticated licensed scan. Factory stamp two
      No Linked Agent row after install  Re-push the MSI  Never linked. Prove linking key / outbound / container
      Agent Offline  Sev-1 platform  Official: Offline after two hours without connect. Quote Last Connect
      Health = Safe Mode  “Online, so it scanned”  Cannot compile plugins or run scans. Recover the agent
      Empty Findings on a live host  Disable the plugin  Last Licensed Scan + agent Status + job Status first
      State = Fixed, weekly still lists it  New critical  Quote Last Fixed. The PDF is stale
      Scan Status = Pending  Launch it again  Queued. Four-hour abort if it stays there. Check overlap
      Running 0% on a small job  Abort and rerun  Official: &lt; 120 IPs = one task; bar jumps 0 → 100
      Scanner Online, VLAN quiet  Hard-restart Nessus  Targets, Network, Warnings, Last Scan Target
      Completed job, old vulns remain  “Scan failed”  Official: inventory-only assets keep reporting until they age out

   Proof checklist before you leave the bridge

- UTC window written next to the tool you opened.

- Host proved in Explore → Assets (Managed or Unmanaged) when the ticket is “is this box in Tenable?”

- One field quoted: Last Seen / Last Scan Time , or Last Authenticated Scan + Last Licensed Scan , or sensor Status + Last Connect , or finding State + Plugin ID , or job Status + Warnings.

- Next tool named — or change-control owner named. No Launch Scan without residual control.

- Peer or second host compared when you claim “not a container outage.”

- Auth-vs-licensed split and Pending-vs-Running not used as the only “Tenable is down” proof.

   Interview close

   I name the question, then the first tool, then one official field. Explore Assets proves the host. Last Authenticated Scan vs Last Licensed Scan proves the assessment. Sensors Last Connect proves the scanner or agent. Findings State + Plugin ID proves the result. Scan Status proves the job. I do not launch a /24, re-push an agent, or disable a plugin until that field is on the ticket. Factory model:  completed ≠ authenticated ≠ exploitable .

## Knowledge check

   Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

       Q1
       Weekly PDF is missing the Finance box. Slack: “Is Tenable even scanning?” You have not opened Findings yet. First proof?

           Launch an unauthenticated Advanced scan of the whole /24
           Explore → Assets — quote the host row (Asset Name + Asset ID + Last Seen) or the official empty search, including Unmanaged if needed
           Explore → Findings for plugin 156999
           Disable the plugin so the PDF shrinks

       Correct:  b . Official Explore Assets inventory. No row means there is no Last Scan Time and no Plugin ID to hunt. Re-read Side A step 1 and TENED-01.

       Q2
       Last Authenticated Scan is last night. Last Licensed Scan is 18 days old. Findings look thin. What is that pair allowed to mean?

           Official: an authenticated discovery-only scan updates Last Authenticated Scan but not Last Licensed Scan — last night may not have been a licensed vulnerability assessment
           The platform is down for the container
           Every Plugin ID on the host is automatically Fixed
           Last Seen is always empty when the two clocks differ

       Correct:  a . Official Asset Columns caveat. The inverse (licensed unauth, no Last Authenticated Scan) is the factory’s failed-auth week. Re-read the callout and TENED-02.

       Q3
       Imaging installed the Tenable Agent at 18:00. Findings are still empty at 02:00. Which proof field closes TENED-03 first?

           Recast the empty Findings list as Accept
           VPR on the weekly PDF cover
           Sensors → Linked Agents: Status + Last Connect + Last Scanned (and Health / Safe Mode)
           WAS Findings for the same hostname

       Correct:  c . Official Agent Status and Linked Agent export fields. No row = not linked. Offline appears after two hours. Safe Mode cannot scan. WAS is a different object. Re-read Side C steps 1–2 and TENED-03.

       Q4
       CISO says plugin 156999 is gone. The weekly still lists it on fin-app-41. First tool + proof?

           Scanner Plugin Set version only
           Explore → Findings: Plugin ID + State + VPR + Last Seen or Last Fixed
           Asset ACR only
           Immediately disable the plugin so the PDF shrinks

       Correct:  b . Official Findings Columns and Vulnerability States (New / Active / Fixed / Resurfaced). Re-read Side B and TENED-04.

       Q5
       Pune VLAN missed the 02:00 job. Slack: “Is the scan actually running?” What do you open first?

           Force-launch every Advanced scan in the folder
           Re-push Tenable Agent to every desk
           Mark every finding Fixed — they must have patched together
           Leave Findings alone. Open Scans → Vulnerability Management Scans and quote Status + Warnings, then Linked Scanners Status

       Correct:  d . Official Scan Status (Pending is not Running; four-hour abort) and scanner Inactive / Routed errors. Re-read Side C steps 3–4 and TENED-05.

       Q6
       The 02:00 job still shows Status = Pending at 03:10. What is that sentence allowed to mean?

           Tenable has the scan queued and is assigning tasks — do not stack another launch; if it stays Pending past four hours Tenable aborts it — check overlapping schedules and the assigned scanner group
           Pending means Completed — close the ticket
           Pending means every Plugin ID is Fixed
           Pending always means the agent is in Safe Mode

       Correct:  a . Official Scan Status: Pending = queued; abort after four hours. Hover Status for targets + elapsed time. Re-read Side C step 4 and TENED-05.

       Check answers
       Reset

## Sources

- Tenable Docs — Asset Columns ( Asset Name , Asset ID , Last Seen , Last Authenticated Scan , Last Licensed Scan , Last Scan Target , Has Plugin Results , Sources )

- Tenable Docs — Explore Assets Export Fields and Associated CSV Keys ( last_scan_time , last_authenticated_scan_time , last_licensed_scan_time , last_scan_id , last_observed , has_agent )

- Tenable Docs — Asset Types (Managed = assessed in 90 days; Unmanaged = discovered, not assessed in 90 days)

- Tenable Docs — View Asset Details

- Tenable Docs — Findings Columns ( Plugin ID , Plugin Name , State , VPR , Severity , First Seen , Last Seen , Last Fixed , Last Authenticated Scan )

- Tenable Docs — Vulnerability States (New, Active, Fixed, Resurfaced)

- Tenable Docs — View Findings Details

- Tenable Docs — Scan Status (Initializing → Running → Publishing Results → Completed; Pending 4-hour abort; Paused 14-day timeout; task %)

- Tenable Docs — Scan Details (Scans → Vulnerability Management Scans; Status, Start Time, Template, Scanner, Targets, Warnings, History)

- Tenable Docs — Scans (inventory-scanned assets keep reporting until they age out)

- Tenable Docs — Error Messages (Agent Unscanned lastConnected/lastScanned; Inactive Scanners; Routed To Inactive Scanners)

- Tenable Docs — View Sensors and Sensor Groups (Status, Health, Last Scanned, Last Plugin Update, Scans count)

- Tenable Docs — Manage Linked Agents (Sensors → Nessus Agents → Linked Agents; Last Connect, Last Scanned, Status)

- Tenable Docs — Agent Status (Online; Offline after two hours; Initializing)

- Tenable Docs — Agents (check-in on start / restart / metadata, no more than every 10 minutes)

- Tenable Docs — Agent Safe Mode (cannot compile plugins or run scans; Overall Health: Safe Mode)

- Tenable Docs — Agent Connection Disruptions (connectivity retry ~30 minutes; offline triggered scans)

 Related:  Blog 1 · Tenable session factory — completed ≠ authenticated ≠ exploitable  ·  Tenable interview hub  ·  VPR prioritization  ·  Nessus scanning  ·  WAS lesson

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
