After reviewing the following vulnerability scanning report: A security analyst performs the following test: Which of the following would the security analyst conclude for this reported vulnerability?
Choose an answer
Tap an option to check your answer.
Correct answer: It is a false positive..
Why this is the answer
The security analyst's test, which indicates the vulnerability is not present, directly contradicts the scanning report. This discrepancy means the scanner incorrectly identified a vulnerability that doesn't actually exist, making it a false positive. A rescan would be needed if the initial scan failed or was incomplete, not when a specific vulnerability is disproven. "Noise" typically refers to irrelevant data or alerts that don't indicate a true security event, but this is a specific, incorrect finding. While compensating controls might exist for a real vulnerability, the analyst's test shows this particular vulnerability is not present at all, so compensating controls are irrelevant to this specific finding.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed