hardMultiple Choice
PT0-002 Practice Question: A vulnerability scanner reports an…
A vulnerability scanner reports an unauthenticated critical finding on an internal server. Manual testing shows the vulnerable package is present, but the vulnerable service is disabled and not reachable. How should the tester report this?
⚠ Common exam trap
A common mix-up: candidates assume any scanner-reported critical finding must be reported as-is, ignoring the penetration tester's duty to validate and contextualize findings based on actual service state and reachability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the finding with contextual risk adjustment and explain that the vulnerable service is disabled and not reachable.
The vulnerability scanner identified a real package vulnerability, but manual verification revealed the service is disabled and unreachable. The tester must report the finding with a contextual risk adjustment to accurately reflect the reduced exploitability, as per standard risk assessment practices in penetration testing. This ensures the organization understands the actual risk without ignoring the presence of the vulnerable package, which could be enabled in the future.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Report the finding with contextual risk adjustment and explain that the vulnerable service is disabled and not reachable.
Why this is correct
Correct. An unauthenticated critical scanner finding must be preserved in the report, but its severity should be contextually adjusted to reflect actual exploitability. Because the vulnerable service is disabled and not reachable, the CVSS base score overstates the real risk; the report should explicitly document the service's disabled state and network isolation to justify a lower residual risk rating while retaining the evidence.
- ✗
Delete the finding because the package exists but is not currently exploitable.
Why it's wrong here
Incorrect. Deleting the finding destroys forensic evidence and violates the principle of maintaining a complete vulnerability record. Even if the package is not currently exploitable because the service is disabled, the condition is still relevant: a future configuration change could enable the service and instantly expose the organization to critical risk, so the finding must be tracked and monitored.
- ✗
Report it as critical without context because the scanner assigned critical severity.
Why it's wrong here
Incorrect. Simply relaying the scanner's assigned critical severity without context fails to validate the result against the actual environment. Scanner severity is a raw base score; it does not account for compensating controls, network reachability, or service state, so reporting it as critical without adjustment would overstate risk and mislead stakeholders who rely on accurate risk prioritization.
- ✗
Exploit the service by enabling it first.
Why it's wrong here
Incorrect. Enabling a disabled service to attempt exploitation is outside the scope of authorized penetration testing and could introduce unnecessary risk or service disruption. Unless the testing rules of engagement explicitly grant permission to change service states, this action violates authorization boundaries and is unethical; the correct behavior is to report the potential vulnerability without forcing it into an exploitable state.
Go deeper
Related to this question
Learn chapter
Phishing Campaigns in Penetration Testing
Key term
Exploitability
Exploitability is a measure of how easy or difficult it is for an attacker to take advantage of a vulnerability in a system or software.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.