PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is analyzing the output of a Nessus vulnerability scan and notices a critical vulnerability reported against a web server that is actually a false positive due to outdated plugin data. What is the best course of action for the tester?
⚠ Common exam trap
Test-takers frequently think a false positive should be removed or ignored outright, but the correct approach is to manually verify the finding to ensure the vulnerability is truly absent before making any reporting decision.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Manually verify the vulnerability by testing it
A false positive due to outdated plugin data must be manually verified before any action is taken. The tester should use a tool like `curl` or a browser to send the exact request that Nessus simulated (e.g., an HTTP GET to a specific endpoint) and inspect the response headers or body to confirm whether the vulnerability actually exists. Only after manual validation can the tester decide to include, exclude, or note the finding in the report.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the finding as accurate and include it in the report
Why it's wrong here
Nessus output should never be treated as ground truth; scanner plugins often produce false positives when service banners are outdated or when dependent on environmental factors such as authentication failures or network restrictions. Accepting the finding without manual verification risks including false positives in the final report, which undermines the penetration test's credibility and may cause the client to waste resources remediating non-existent issues.
- ✗
Remove the finding from the report entirely
Why it's wrong here
Removing the finding from the report entirely violates established penetration testing methodology, such as PTES's report phase, which requires all discovered issues to be documented and triaged. Even if the Nessus result appears dubious, it could represent an actual vulnerability that would be missed if simply discarded; the proper action is further investigation, not unilateral deletion.
- ✓
Manually verify the vulnerability by testing it
Why this is correct
Manual verification entails actively reproducing the vulnerability—e.g., sending a crafted HTTP request to confirm a SQL injection, or checking if a specific CVE applies by reviewing patch levels and exploiting the target in a controlled manner. This step distinguishes real security gaps from false positives generated by the scanner, and also collects proof-of-concept evidence necessary for a credible, actionable penetration test report.
- ✗
Ignore the finding because it's a false positive
Why it's wrong here
Labeling the Nessus output as a false positive without performing any verification is negligent because scanners can misclassify vulnerabilities due to incomplete plugin coverage or credential-based access limitations, and they may also underestimate real risk. A valid finding could be ignored, leaving the organization exposed; proper analyst investigation, including command-line probes or retesting with alternative scanners, is essential before dismissing any result.
Go deeper
Related to this question
Learn chapter
Writing Penetration Test Reports
Key term
Nessus
Nessus is a vulnerability scanner that automatically identifies security weaknesses, missing patches, and misconfigurations in computer systems and networks.
Key term
False positive
A false positive is an alert or result that indicates a security threat or vulnerability exists when in fact there is no real issue.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.