Which of the following is the primary reason why false negatives on a vulnerability scan should be a concern?
Choose an answer
Tap an option to check your answer.
Correct answer: The system has vulnerabilities that are not being detected..
Why this is the answer
A false negative in a vulnerability scan means the scan failed to identify an existing vulnerability. This is a significant concern because it leaves the organization with a false sense of security, believing a system is secure when it actually has exploitable weaknesses. These undetected vulnerabilities can then be exploited by attackers, leading to data breaches, system compromise, or other security incidents. The other options are incorrect because: "The time to remediate vulnerabilities that do not exist is excessive" describes a false positive, not a false negative. "Vulnerabilities with a lower severity will be prioritized over critical vulnerabilities" is a prioritization issue, not directly caused by false negatives. False negatives mean critical vulnerabilities might not even appear on the list. "The system has vulnerabilities, and a patch has not yet been released" describes a zero-day vulnerability or an unpatched known vulnerability, which is a separate issue from a scan failing to detect an existing vulnerability.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed