CompTIA Security+ (SY0-701)Security OperationsHard
A vulnerability scanner flags a web server as having a critical remote code execution vulnerability. During manual verification, the security analyst confirms the relevant patch was already applied and the specific vulnerable code path is unreachable. How should this finding be classified?
- ATrue positive
- BTrue negative
- CFalse positive
- DFalse negative
Show answer & explanationAnswer & explanation
Correct answer: C. False positive
A false positive occurs when a scanner reports a vulnerability that does not actually exist on the target after manual verification—here the patch was already applied and the code path unreachable. A true positive would require the vulnerability to genuinely exist; a false negative is a missed real vulnerability; a true negative is correctly reporting no vulnerability, which doesn't apply since the scanner did alert.
Why the other options are wrong
- A. True positive requires the flagged vulnerability to actually be present.
- B. True negative applies when no alert is raised and no vulnerability exists.
- D. False negative would mean a real vulnerability was missed, opposite of this case.
False Positive (Vulnerability Scanning)
An alert indicating a vulnerability exists when, upon verification, it actually does not, often due to outdated scanner signatures or environmental context.
- Wastes analyst time if not verified
- Common with credentialed vs uncredentialed scans
- Manual validation reduces false positive rate
Memory trick: A false positive is a smoke alarm 🚨 going off from toast, not an actual fire.