Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementEasy
A security analyst is investigating a reported vulnerability in an internal web application. The vulnerability scanner flagged a potential 'SQL Injection' due to unsanitized input fields. However, after reviewing the application's source code, the development team confirms that all user inputs are rigorously validated and parameterized queries are used throughout the application. What is the MOST appropriate classification for this vulnerability report?
- ATrue Positive
- BFalse Positive
- CFalse Negative
- DTrue Negative
Show answer & explanationAnswer & explanation
Correct answer: B. False Positive
A false positive occurs when a security tool or system incorrectly identifies a threat or vulnerability that does not actually exist. In this case, the scanner flagged SQL Injection, but code review confirmed it was not present due to proper sanitization and parameterized queries.
Why the other options are wrong
- A. A true positive means the scanner correctly identified an actual vulnerability.
- C. A false negative means the scanner missed an actual vulnerability.
- D. A true negative means the scanner correctly identified that no vulnerability exists.
False Positive (Vulnerability Assessment)
A false positive in vulnerability assessment is an erroneous report by a security tool, indicating the presence of a vulnerability that, upon further investigation, is determined not to exist.
- Can lead to wasted effort in remediation.
- Often requires manual verification to differentiate from true positives.
- Common in automated scanning due to heuristic analysis or outdated signatures.
Memory trick: SCAN RESULTS: True/False, Positive/Negative.