PT0-002 Reconnaissance and Enumeration Practice Question
A penetration tester is performing a vulnerability scan on a web server using Nikto. After the scan, the tester notices several findings related to outdated software versions and missing security headers. What should the tester do to validate the findings and reduce false positives?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Manually verify a subset of the findings
Manually verifying findings is the best practice to confirm if they are real vulnerabilities or false positives. Relying on scanner output alone is insufficient.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore findings related to missing headers as low priority
Why it's wrong here
Ignoring missing headers findings as low priority is inadvisable because headers such as Strict-Transport-Security, X-Frame-Options, and Content-Security-Policy play a critical security role; their absence can enable clickjacking, protocol downgrade attacks, or content injection. Even if Nikto classifies them as informational or low risk, a penetration tester should verify each finding and assess the real-world exploitability within the target environment, rather than dismissing them outright.
- ✓
Manually verify a subset of the findings
Why this is correct
Manually verifying a subset of the findings is the correct next step after an automated scan, because tools like Nikto rely on signature matching and often produce false positives that don't reflect the actual application behavior. By using techniques such as inspecting raw HTTP responses, confirming server headers, or re-checking vulnerable files with curl, the tester can confirm whether a finding represents a genuine vulnerability, gauge the scanner's accuracy, and prioritize remediation based on validated evidence.
- ✗
Increase the scan intensity to get more details
Why it's wrong here
Increasing scan intensity (e.g., higher nmap timing, deeper directory brute force, or more aggressive Nikto tuning) may yield additional data, but it also raises the risk of false positives, server load, or even crashing the target. More importantly, it doesn't address the core problem: existing scan results still need validation, and aggressive scanning could introduce new variables or inconsistencies, making the findings even harder to interpret rather than clearer.
- ✗
Accept all findings as true since Nikto is a reliable tool
Why it's wrong here
While Nikto is a widely used and respected web vulnerability scanner, it is not a substitute for human judgment; its database of tests can flag benign files, outdated software versions, or missing headers that are not actually exploitable in the specific context. Blindly accepting every automated result as true would lead to wasted resources chasing phantom issues and could obscure real, verified vulnerabilities in the final report, so every finding must be correlated with manual inspection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.