mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is using a vulnerability…
A penetration tester is using a vulnerability scanner on a web application and notices that many findings are false positives caused by the scanner sending oversized payloads that the application truncates or rejects. Which scanner configuration change would MOST effectively reduce false positives in this scenario?
⚠ Common exam trap
Many candidates confuse 'increasing scan intensity' with 'more thorough testing,' but in reality, it amplifies the very behavior (oversized payloads) that causes false positives, while 'safe checks' directly mitigates the root cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable safe checks or anti-false positive mode
Enabling safe checks or anti-false positive mode configures the scanner to send payloads that conform to expected application input constraints (e.g., length limits, character sets) rather than oversized or malformed payloads. This reduces false positives by ensuring that the scanner only reports vulnerabilities that are actually reachable and exploitable under normal application behavior, rather than triggering truncation or rejection logic that is not a security flaw.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the scan intensity to send more payloads
Why it's wrong here
Increasing scan intensity instructs the scanner to send a greater volume of payloads and adjust fuzzing depth, but it does not add any post-detection verification for the results. More aggressive payload injection often triggers more edge-case responses, which actually increases the likelihood of false positives rather than reducing them. The goal of reducing false positives requires validation logic, not simply more test cases.
- ✓
Enable safe checks or anti-false positive mode
Why this is correct
Enabling safe checks (or anti-false positive mode) forces the scanner to perform an additional verification pass, typically by sending a benign follow-up request or analyzing the response against a baseline, before a finding is reported as a vulnerability. This confirmatory step distinguishes real, exploitable conditions from noise, such as default error pages or generic server responses. It is the standard configuration for minimizing false positives while retaining true positive detection.
- ✗
Increase the HTTP request timeout
Why it's wrong here
Raising the HTTP request timeout only extends the period the scanner waits for a server response; it does nothing to refine how responses are interpreted for vulnerability confirmation. A longer timeout helps with slow endpoints or network latency, but it cannot correct the core issue of a response being misclassified as vulnerable. In fact, an excessively long timeout may cause the scan to hang or miss real timeout-based vulnerabilities, yet it never reduces false positives.
- ✗
Disable vulnerability detection for certain plugins
Why it's wrong here
Disabling vulnerability detection for certain plugins is a blunt, overly broad action that removes entire checks from the scan engine, which also eliminates the chance of finding genuine issues tied to those plugins. While it might occasionally reduce false positives in a specific plugin, it does not address the underlying detection logic that causes false positives elsewhere, and it sacrifices real vulnerability coverage. This approach is never recommended as a curated method to improve reporting accuracy; instead, one should tune the scanner's verification settings.
Go deeper
Related to this question
Learn chapter
Operational Security (OPSEC) for PenTesters
Key term
Vulnerability scanner
A vulnerability scanner is an automated tool that identifies security weaknesses in systems, networks, and applications by comparing their configurations and software versions against known vulnerability databases.
Key term
False positive
A false positive is an alert or result that indicates a security threat or vulnerability exists when in fact there is no real issue.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.