If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.
Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer...