Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementMedium

A security analyst is reviewing a vulnerability scan report that lists several findings. One particular finding is rated 'High' severity and details a missing security update for an operating system component that allows remote code execution. However, the analyst knows the component is not installed or used on the affected servers. What is the most appropriate classification for this finding in the context of the organization's risk?

  1. AFalse Positive
  2. BTrue Negative
  3. CFalse Negative
  4. DTrue Positive
Show answer & explanation

Correct answer: A. False Positive

A false positive occurs when a vulnerability scanner reports a vulnerability that does not actually exist or is not exploitable in the specific environment. In this case, the component is not present, so the vulnerability is not real for that system.

Why the other options are wrong

  • B. A true negative is a correct identification that no vulnerability exists when it truly doesn't.
  • C. A false negative is a missed vulnerability; the scanner fails to report an existing flaw.
  • D. A true positive is a correctly identified vulnerability that genuinely exists.

False Positive (Vulnerability Scan)

A vulnerability scan result that indicates a security flaw when, in reality, no such flaw exists in the target system or is not exploitable in that specific context.

  • Can waste time and resources in remediation efforts.
  • Often due to incomplete scanner knowledge or environmental factors.
  • Requires manual validation to differentiate from true positives.

Memory trick: Positive means found, False means wrong.

More Vulnerability Management questions