CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy

A vulnerability scanner flags a Linux server as affected by a specific Apache HTTP Server CVE based solely on the version string reported in the server's HTTP banner. During manual verification, the analyst confirms the vendor backported the security fix into this version and the vulnerable code path is no longer present. How should this scan result be classified?

  1. AFalse positive
  2. BFalse negative
  3. CTrue positive
  4. DTrue negative
Show answer & explanation

Correct answer: A. False positive

The scanner reported a vulnerability that does not actually exist because the patch was backported without changing the version string, making this a false positive. Banner-based (non-credentialed) detection is prone to this error.

Why the other options are wrong

  • B. A false negative is a missed vulnerability, not an incorrectly flagged one.
  • C. A true positive would mean the vulnerability genuinely exists.
  • D. A true negative would mean the scanner correctly reported no vulnerability.

False Positive

A false positive occurs when a scanner reports a vulnerability that does not actually exist on the target system.

  • Common with version-banner-based detection
  • Backported patches often cause false positives
  • Manual verification reduces wasted remediation effort

Memory trick: Positive = flagged, Negative = clear; True = correct, False = wrong

More Vulnerability Management questions