CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

An automated scanner flags a web server as vulnerable to a critical remote code execution CVE based on the reported software version banner. When the penetration tester manually attempts to trigger the exploit, the server rejects it because the vendor's patch was actually applied but the version string was not updated. How should the tester classify this scanner finding?

  1. ATrue positive
  2. BFalse positive
  3. CTrue negative
  4. DFalse negative
Show answer & explanation

Correct answer: B. False positive

A false positive occurs when a scanner reports a vulnerability that does not actually exist. Here, the scanner relied on an inaccurate version banner and incorrectly flagged a patched system as vulnerable, which manual validation disproved.

Why the other options are wrong

  • A. A true positive would mean the vulnerability was confirmed to exist, which it was not.
  • C. A true negative would mean the scanner correctly reported no vulnerability, but it did report one.
  • D. A false negative would mean an existing vulnerability was missed, the opposite of this scenario.

False Positive

A scan result indicating a vulnerability exists when it actually does not, often due to unreliable version/banner-based detection.

  • Common cause: banner grabbing without verifying actual patch level
  • Manual validation/exploitation confirms or disproves findings
  • Credentialed scans reduce false positive rates

Memory trick: TP=真, FP=Fake alarm, FN=Missed danger, TN=真 clear

More Vulnerability Discovery and Analysis questions