CompTIA Security+ (SY0-701)Security OperationsMedium

A security team is regularly reviewing vulnerability scan reports. They frequently encounter findings that are flagged as 'High' severity but, after manual inspection, are determined to pose no actual risk due to compensating controls or environmental factors. What process should the team implement to reduce the noise from these non-actionable findings in future reports?

  1. AImplement a SIEM solution
  2. BApply a patch management policy
  3. CIncrease scan frequency
  4. DTune vulnerability scanner settings
Show answer & explanation

Correct answer: D. Tune vulnerability scanner settings

Tuning vulnerability scanner settings allows administrators to customize scan parameters, exclude certain findings, or adjust severity levels based on organizational context, thereby reducing false positives and focusing on actionable vulnerabilities.

Why the other options are wrong

  • A. Implementing a SIEM solution aggregates and correlates logs but doesn't directly control the output or false positives generated by a vulnerability scanner.
  • B. Applying a patch management policy addresses actual vulnerabilities but doesn't prevent false positives or irrelevant findings from appearing in reports.
  • C. Increasing scan frequency would generate more reports with the same 'noisy' findings, not reduce them.

Vulnerability Scanner Tuning

The process of adjusting the configuration and parameters of a vulnerability scanner to optimize its performance, reduce false positives, and ensure relevant results.

  • Reduces 'noise' in scan reports.
  • Customizes scans to organizational context.
  • Improves accuracy and actionability of findings.

Memory trick: To make the scanner 'sing' a clearer tune, you need to 'tune' its settings.

More Security Operations questions