What you are evaluating
Cloud agents, passive sensors, and container sensors sit beside network scanning. Assessment coverage and remediation-module entitlements should be treated as separate commercial and operational questions, including how TruRisk relates to KEV and EPSS.
A useful evaluation context
A plausible evaluation context is an organization that already runs Qualys sensors and needs to test authenticated coverage, TruRisk explainability, and whether remediation modules are actually entitled.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Asset and vulnerability assessment using network scans, cloud agents, passive sensors, and container sensors.
- Threat context and patch workflows attached to assessed findings.
- Enterprise TruRisk Management aggregation across Qualys and third-party tools, with a vendor risk score that still needs ingredient-level review.
Where it fits in the work
- Choose authenticated scanning, agents, or both for owned systems, and record which unmanaged or air-gapped assets remain out of reach.
- Export findings with technical severity, exploitation evidence, and TruRisk values as separate fields so a reviewer can reconstruct priority.
- Use entitled patch or ticket workflows, record compensating controls when a fix is deferred, and re-assess after the change.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
On lab hosts you own, deploy a Qualys assessment path you are entitled to use. Plant one outdated package and one configuration weakness. Keep a second host without credentials so coverage gaps are visible.
Evidence to look for
The credentialed host reports the planted weakness, the unauthenticated host is visibly uncovered or thinner, exported columns retain separate severity and threat fields, and a documented patch or exception can be re-assessed.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- What share of in-scope assets have recent authenticated or agent assessments versus unauthenticated probes?
- Can operators show KEV, EPSS, and CVSS beside TruRisk, or does the score hide those ingredients?
- Which remediation and aggregation modules are in the contract, and how are duplicate or ephemeral assets counted?
Names you may encounter: Qualys VMDR · Enterprise TruRisk Platform. Historical names do not establish current availability or feature equivalence.