An agent-based scan relies on software installed directly on the endpoint to collect local system state and report vulnerability or configuration information to the management platform. Because the agent has local visibility, its findings can be influenced by endpoint configuration, agent policy, update state, privileges, enabled assessment modules, or configuration changes that determine what information is collected and evaluated.
The scenario indicates that regularly scheduled assessment activity initially failed to identify the newly disclosed vulnerability, but the condition became visible after a configuration change. Among the available choices, that behavior most strongly aligns with an agent-based assessment whose local collection or assessment configuration had to be updated before the vulnerability could be detected.
An external scan evaluates systems from outside the organizational boundary and focuses primarily on externally reachable services. A network scan examines hosts and services remotely and is governed mainly by network reachability and scanner capabilities. A credentialed scan authenticates into a system to obtain deeper visibility, but the defining characteristic in the question is the persistent endpoint-based assessment affected by configuration.
CySA+ vulnerability-management objectives distinguish assessment techniques by perspective, authentication level, deployment method, and resulting visibility. Analysts must understand why different scanning architectures can produce different findings.
Study Guide Reference: Vulnerability Management → Vulnerability Scanning Methods → Agent-Based Scanning → Network Scanning → Credentialed Scanning → Scan Configuration and Coverage.