PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is conducting a vulnerability assessment and wants to minimize false positives. Which THREE actions should the tester take? (Select THREE.)
⚠ Common exam trap
Test-takers frequently think running the same scan multiple times (Option A) improves accuracy, but it actually increases noise without validating findings, whereas manual verification and cross-referencing are the proven methods to minimize false positives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify findings manually
Option B (Verify findings manually) is correct because manual validation confirms whether a scanner-detected vulnerability is actually exploitable and present, eliminating false positives that automated tools report due to version banners or heuristics. Option C (Cross-reference results with multiple scanners) is correct because different scanners use distinct detection signatures and logic, so correlating findings across tools (e.g., Nessus, OpenVAS, Qualys) helps filter out tool-specific false positives and increases confidence in true findings. Option E (Use authenticated scanning where possible) is correct because credentialed scans log into the target and inspect actual patch levels, configurations, and installed software rather than inferring from remote banners, dramatically reducing false positives. Option A (Run the same scan multiple times) is not correct because repetition with the same tool and signatures does not resolve false positives and may simply reproduce the same erroneous results. Option D (Ignore all high-severity findings initially) is not correct because dismissing high-severity findings without validation risks missing genuine critical vulnerabilities and does not address false-positive reduction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run the same scan multiple times
Why it's wrong here
Running the identical scan repeatedly with the same tool, configuration, and credentials will produce deterministic results for a static environment; it does not introduce new evidence or contextual analysis to disambiguate between true vulnerabilities and false positives. False positives often stem from banner grabbing, service version inference, or missing patch-state verification, and re-scanning will merely re-report the same inconclusive data. To reduce false positives, you must change the verification methodology, not the repetition count.
- ✓
Verify findings manually
Why this is correct
Manual verification involves a human analyst inspecting the actual service, configuration, or response to determine if the scanner's reported condition truly exists and is exploitable. For example, a scanner may flag a TLS version based on advertised ciphers, but manual testing (e.g., checking effective protocols via openssl or reviewing server config) can confirm if the issue is real or a misconfiguration that doesn't apply. This step is the gold standard for eliminating false positives because it applies context, logic, and exploitability assessment that automated tools lack.
- ✓
Cross-reference results with multiple scanners
Why this is correct
When two or more independent scanners (e.g., Nessus and OpenVAS) both report the same vulnerability with corroborating evidence, confidence increases dramatically; conversely, if only one tool flags an issue and the other does not despite similar coverage, the finding is often a false positive or a tool-specific artifact. This approach leverages divergent detection engines, plugin sets, and fingerprinting methods to triangulate on truth. However, it is not a complete substitute for manual validation because all scanners may share the same plugin logic or library (e.g., both using Nmap's version detection), creating correlated false positives.
- ✗
Ignore all high-severity findings initially
Why it's wrong here
High-severity findings, such as remote code execution or SQL injection, demand immediate investigation because they represent the highest risk to the organization; deferring or ignoring them based on a fear of false positives could leave critical vulnerabilities unmitigated. False positives are less common for high-severity items, but when they do occur, they must be confirmed quickly via manual testing or exploitation attempts, not assumed away. Proper triage processes prioritize investigating all high-severity findings, not ignoring them, to avoid missing a genuine attack vector.
- ✓
Use authenticated scanning where possible
Why this is correct
Authenticated scanning uses valid credentials to query the target OS and installed applications via APIs (e.g., WMI, SSH, SNMP) or local file access, allowing the scanner to see patch levels, configuration settings, and software inventories directly rather than inferring them from network banners or version strings. This eliminates the primary source of false positives—guesswork based on banner and service fingerprinting—by checking for the actual presence and applicability of vulnerabilities (e.g., looking for a specific file version or registry key). It also reduces false negatives, as it can detect missing patches that may be masked by custom banner strings.
Visual reference
Go deeper
Related to this question
Learn chapter
Red Team Exercises vs Penetration Tests
Key term
OpenVAS
OpenVAS is an open-source vulnerability scanner that helps IT professionals identify security weaknesses in networks, systems, and applications.
Key term
Nessus
Nessus is a vulnerability scanner that automatically identifies security weaknesses, missing patches, and misconfigurations in computer systems and networks.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.