Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

A penetration tester is conducting a vulnerability assessment and wants to minimize false positives. Which THREE actions should the tester take? (Select THREE.)

⚠ Common exam trap

Test-takers frequently think running the same scan multiple times (Option A) improves accuracy, but it actually increases noise without validating findings, whereas manual verification and cross-referencing are the proven methods to minimize false positives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify findings manually

Option B (Verify findings manually) is correct because manual validation confirms whether a scanner-detected vulnerability is actually exploitable and present, eliminating false positives that automated tools report due to version banners or heuristics. Option C (Cross-reference results with multiple scanners) is correct because different scanners use distinct detection signatures and logic, so correlating findings across tools (e.g., Nessus, OpenVAS, Qualys) helps filter out tool-specific false positives and increases confidence in true findings. Option E (Use authenticated scanning where possible) is correct because credentialed scans log into the target and inspect actual patch levels, configurations, and installed software rather than inferring from remote banners, dramatically reducing false positives. Option A (Run the same scan multiple times) is not correct because repetition with the same tool and signatures does not resolve false positives and may simply reproduce the same erroneous results. Option D (Ignore all high-severity findings initially) is not correct because dismissing high-severity findings without validation risks missing genuine critical vulnerabilities and does not address false-positive reduction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run the same scan multiple times

    Why it's wrong here

    Running the identical scan repeatedly with the same tool, configuration, and credentials will produce deterministic results for a static environment; it does not introduce new evidence or contextual analysis to disambiguate between true vulnerabilities and false positives. False positives often stem from banner grabbing, service version inference, or missing patch-state verification, and re-scanning will merely re-report the same inconclusive data. To reduce false positives, you must change the verification methodology, not the repetition count.

  • ✓

    Verify findings manually

    Why this is correct

    Manual verification involves a human analyst inspecting the actual service, configuration, or response to determine if the scanner's reported condition truly exists and is exploitable. For example, a scanner may flag a TLS version based on advertised ciphers, but manual testing (e.g., checking effective protocols via openssl or reviewing server config) can confirm if the issue is real or a misconfiguration that doesn't apply. This step is the gold standard for eliminating false positives because it applies context, logic, and exploitability assessment that automated tools lack.

  • ✓

    Cross-reference results with multiple scanners

    Why this is correct

    When two or more independent scanners (e.g., Nessus and OpenVAS) both report the same vulnerability with corroborating evidence, confidence increases dramatically; conversely, if only one tool flags an issue and the other does not despite similar coverage, the finding is often a false positive or a tool-specific artifact. This approach leverages divergent detection engines, plugin sets, and fingerprinting methods to triangulate on truth. However, it is not a complete substitute for manual validation because all scanners may share the same plugin logic or library (e.g., both using Nmap's version detection), creating correlated false positives.

  • ✗

    Ignore all high-severity findings initially

    Why it's wrong here

    High-severity findings, such as remote code execution or SQL injection, demand immediate investigation because they represent the highest risk to the organization; deferring or ignoring them based on a fear of false positives could leave critical vulnerabilities unmitigated. False positives are less common for high-severity items, but when they do occur, they must be confirmed quickly via manual testing or exploitation attempts, not assumed away. Proper triage processes prioritize investigating all high-severity findings, not ignoring them, to avoid missing a genuine attack vector.

  • ✓

    Use authenticated scanning where possible

    Why this is correct

    Authenticated scanning uses valid credentials to query the target OS and installed applications via APIs (e.g., WMI, SSH, SNMP) or local file access, allowing the scanner to see patch levels, configuration settings, and software inventories directly rather than inferring them from network banners or version strings. This eliminates the primary source of false positives—guesswork based on banner and service fingerprinting—by checking for the actual presence and applicability of vulnerabilities (e.g., looking for a specific file version or registry key). It also reduces false negatives, as it can detect missing patches that may be masked by custom banner strings.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.