Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is analyzing the output of a Nessus vulnerability scan and notices a critical vulnerability reported against a web server that is actually a false positive due to outdated plugin data. What is the best course of action for the tester?

⚠ Common exam trap

Test-takers frequently think a false positive should be removed or ignored outright, but the correct approach is to manually verify the finding to ensure the vulnerability is truly absent before making any reporting decision.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Manually verify the vulnerability by testing it

A false positive due to outdated plugin data must be manually verified before any action is taken. The tester should use a tool like `curl` or a browser to send the exact request that Nessus simulated (e.g., an HTTP GET to a specific endpoint) and inspect the response headers or body to confirm whether the vulnerability actually exists. Only after manual validation can the tester decide to include, exclude, or note the finding in the report.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accept the finding as accurate and include it in the report

    Why it's wrong here

    Nessus output should never be treated as ground truth; scanner plugins often produce false positives when service banners are outdated or when dependent on environmental factors such as authentication failures or network restrictions. Accepting the finding without manual verification risks including false positives in the final report, which undermines the penetration test's credibility and may cause the client to waste resources remediating non-existent issues.

  • ✗

    Remove the finding from the report entirely

    Why it's wrong here

    Removing the finding from the report entirely violates established penetration testing methodology, such as PTES's report phase, which requires all discovered issues to be documented and triaged. Even if the Nessus result appears dubious, it could represent an actual vulnerability that would be missed if simply discarded; the proper action is further investigation, not unilateral deletion.

  • ✓

    Manually verify the vulnerability by testing it

    Why this is correct

    Manual verification entails actively reproducing the vulnerability—e.g., sending a crafted HTTP request to confirm a SQL injection, or checking if a specific CVE applies by reviewing patch levels and exploiting the target in a controlled manner. This step distinguishes real security gaps from false positives generated by the scanner, and also collects proof-of-concept evidence necessary for a credible, actionable penetration test report.

  • ✗

    Ignore the finding because it's a false positive

    Why it's wrong here

    Labeling the Nessus output as a false positive without performing any verification is negligent because scanners can misclassify vulnerabilities due to incomplete plugin coverage or credential-based access limitations, and they may also underestimate real risk. A valid finding could be ignored, leaving the organization exposed; proper analyst investigation, including command-line probes or retesting with alternative scanners, is essential before dismissing any result.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.