CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium
An organization runs an automated vulnerability scan against its web servers. Weeks later, a manual penetration test uncovers an unpatched, actively exploitable OpenSSL vulnerability that the scanner never flagged. How should this scanning outcome be classified?
- ATrue positive
- BFalse positive
- CTrue negative
- DFalse negative
Show answer & explanationAnswer & explanation
Correct answer: D. False negative
A false negative occurs when a real vulnerability exists but the scanner fails to detect and report it, which is exactly what happened here.
Why the other options are wrong
- A. A true positive would mean the scanner correctly reported the flaw.
- B. A false positive is an incorrectly reported vulnerability that doesn't actually exist.
- C. A true negative means no vulnerability exists and none was reported.
False Negative
A scan result where an actual vulnerability exists on the target but the scanning tool fails to identify or report it.
- Often caused by outdated plugin/signature databases
- More dangerous than false positives since risk goes unnoticed
- Manual validation and multiple scanners help reduce false negatives
Memory trick: 'Truth Tells, False Fools' — match reality vs. report