CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

An organization runs an automated vulnerability scan against its web servers. Weeks later, a manual penetration test uncovers an unpatched, actively exploitable OpenSSL vulnerability that the scanner never flagged. How should this scanning outcome be classified?

  1. ATrue positive
  2. BFalse positive
  3. CTrue negative
  4. DFalse negative
Show answer & explanation

Correct answer: D. False negative

A false negative occurs when a real vulnerability exists but the scanner fails to detect and report it, which is exactly what happened here.

Why the other options are wrong

  • A. A true positive would mean the scanner correctly reported the flaw.
  • B. A false positive is an incorrectly reported vulnerability that doesn't actually exist.
  • C. A true negative means no vulnerability exists and none was reported.

False Negative

A scan result where an actual vulnerability exists on the target but the scanning tool fails to identify or report it.

  • Often caused by outdated plugin/signature databases
  • More dangerous than false positives since risk goes unnoticed
  • Manual validation and multiple scanners help reduce false negatives

Memory trick: 'Truth Tells, False Fools' — match reality vs. report

More Vulnerability Discovery and Analysis questions