CompTIA Security+ (SY0-701)Security OperationsMedium
A security team is regularly reviewing vulnerability scan reports. They frequently encounter findings for critical systems that, upon manual inspection, are determined to be false positives due to compensating controls or environmental factors not understood by the scanner. This situation is leading to alert fatigue and wasted effort. Which aspect of vulnerability management needs improvement?
- AVulnerability remediation
- BThreat intelligence integration
- CVulnerability prioritization
- DFalse positive tuning
Show answer & explanationAnswer & explanation
Correct answer: D. False positive tuning
The scenario describes a high rate of false positives from vulnerability scans, leading to wasted effort. 'False positive tuning' directly addresses this issue by refining scan configurations, providing context to the scanner, or adjusting reporting to accurately reflect the true risk posture, thereby reducing alert fatigue.
Why the other options are wrong
- A. Remediation is fixing actual vulnerabilities, not addressing false positives.
- B. Threat intelligence integration helps identify *new* threats or validate *real* vulnerabilities, but doesn't inherently solve false positive issues from existing scans.
- C. Prioritization focuses on which *real* vulnerabilities to fix first, not on eliminating invalid findings.
False Positive Tuning (Vulnerability Management)
The process of refining vulnerability scanner configurations, adding exclusions, or providing contextual information to reduce the number of erroneous alerts that are not true vulnerabilities.
- Reduces alert fatigue and wasted effort for security teams.
- Involves understanding compensating controls or environmental factors.
- Can include adjusting scan policies, creating custom checks, or using exceptions.
Memory trick: To tune out false positives, you need 'Fine-Tuning' of the scanner.