Yes, you can safely run the scan during peak or off-peak hours. The scan only requires read access to the configuration and logs and is not intensive on SBC compute, memory or network. It is preferable to run it during off-peak hours.
Access to the SBC (EMS) is required to run the scan. The access can be direct network access (the scanner is in the same WAN network as the SBC), via VPN or via SAL.
Not really. The scan attempts to find as many security vulnerabilities in your SBC as possible, but it does not claim to find 100% of issues. Also do note that attacks can happen at any time, even immediately after the scan completes. Security is a ...