Scanners are the cheapest security coverage available and the easiest to run badly.
Credentialed beats uncredentialed
An unauthenticated scan sees what a stranger sees: open ports and banner guesses, with false positives in both directions. A credentialed scan reads installed package versions and configuration, and is dramatically more accurate. If you run only one, run the credentialed one — and treat the scanning account as the privileged credential it is.
Coverage is the real problem
Most programmes do not have a scanner accuracy problem; they have an asset problem. The host that gets compromised is usually the one nobody knew about, which no scan covered. Reconcile scan coverage against the asset inventory, the cloud provider's API and DNS, and investigate the gap.
Tuning
A scanner that reports forty thousand findings is reporting nothing. Suppress by reason, with an owner and a review date — never silently. Group by patch and by image, since one base image update often closes thousands of findings at once.
Metrics worth keeping
Not "findings closed", which rewards closing easy ones. Better: time to remediate by severity, the proportion of assets scanned in the last 30 days, and the age of the oldest unremediated critical. Those three say more about a programme than any count.