A credentialed vulnerability scan of a Linux server returns zero findings. During a manual review, an analyst discovers the installed OpenSSL package is affected by a critical, publicly known CVE. Investigation shows the scanning service account's password had expired the night before the scan, causing authentication to silently fail while the scanner still returned a status of 'completed' after falling back to limited host discovery. How should this scan result be classified?
- AFalse negative, caused by an authentication failure that silently reduced the scan to an unauthenticated/limited check
- BTrue negative, because the OpenSSL vulnerability does not apply to this server's configuration
- CFalse positive, caused by the scanner incorrectly flagging a vulnerability that does not exist
- DTrue positive, because the scanner correctly reported no findings for the tested scope
Show answer & explanationAnswer & explanation
Correct answer: A. False negative, caused by an authentication failure that silently reduced the scan to an unauthenticated/limited check
A false negative occurs when an actual vulnerability exists but the scan fails to detect it. Here, the expired credentials caused the scan to silently degrade to a limited, unauthenticated-style check, so the real critical OpenSSL vulnerability went undetected despite being present, meeting the definition of a false negative.
Why the other options are wrong
- B. The vulnerability was confirmed to affect the server, so this is not a true negative.
- C. False positives involve incorrectly reporting a vulnerability that isn't there, the opposite of what happened.
- D. A true positive requires a real finding to be correctly reported; here nothing was reported at all.
False Negative (Vulnerability Scanning)
A scan result classification where an actual vulnerability exists on the target but the scan fails to detect or report it, often due to scan scope limitations, credential failures, or evasion.
- Common causes: expired/invalid credentials, firewall blocking, scan scope exclusions
- More dangerous than false positives because risk goes unnoticed
- Credentialed scans that silently degrade to unauthenticated mode are a key false-negative risk
Memory trick: Expired password = the scanner peeked through a locked window and missed what's inside.