CompTIA CySA+ (CS0-003)Vulnerability ManagementHard

A credentialed vulnerability scan of a Linux server returns zero findings. During a manual review, an analyst discovers the installed OpenSSL package is affected by a critical, publicly known CVE. Investigation shows the scanning service account's password had expired the night before the scan, causing authentication to silently fail while the scanner still returned a status of 'completed' after falling back to limited host discovery. How should this scan result be classified?

  1. AFalse negative, caused by an authentication failure that silently reduced the scan to an unauthenticated/limited check
  2. BTrue negative, because the OpenSSL vulnerability does not apply to this server's configuration
  3. CFalse positive, caused by the scanner incorrectly flagging a vulnerability that does not exist
  4. DTrue positive, because the scanner correctly reported no findings for the tested scope
Show answer & explanation

Correct answer: A. False negative, caused by an authentication failure that silently reduced the scan to an unauthenticated/limited check

A false negative occurs when an actual vulnerability exists but the scan fails to detect it. Here, the expired credentials caused the scan to silently degrade to a limited, unauthenticated-style check, so the real critical OpenSSL vulnerability went undetected despite being present, meeting the definition of a false negative.

Why the other options are wrong

  • B. The vulnerability was confirmed to affect the server, so this is not a true negative.
  • C. False positives involve incorrectly reporting a vulnerability that isn't there, the opposite of what happened.
  • D. A true positive requires a real finding to be correctly reported; here nothing was reported at all.

False Negative (Vulnerability Scanning)

A scan result classification where an actual vulnerability exists on the target but the scan fails to detect or report it, often due to scan scope limitations, credential failures, or evasion.

  • Common causes: expired/invalid credentials, firewall blocking, scan scope exclusions
  • More dangerous than false positives because risk goes unnoticed
  • Credentialed scans that silently degrade to unauthenticated mode are a key false-negative risk

Memory trick: Expired password = the scanner peeked through a locked window and missed what's inside.

More Vulnerability Management questions