PT0-002 Reconnaissance and Enumeration Practice Question
When performing vulnerability scanning, which of the following best describes a false positive?
⚠ Common exam trap
Candidates often confuse false positives with false negatives; candidates often pick option D because they misremember the definition, but false negatives are missed vulnerabilities, not incorrect reports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A vulnerability that the scanner reports but does not actually exist.
A false positive in vulnerability scanning occurs when the scanner reports a vulnerability that does not actually exist. This is option C. False positives are caused by factors such as overly aggressive signature matching, misconfigured scan profiles, or incomplete verification of service responses. They waste resources by prompting unnecessary remediation efforts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A vulnerability that is correctly identified and verified.
Why it's wrong here
A finding that is correctly identified and verified is a true positive, not a false positive. During a scan, the scanner may flag a service or configuration that genuinely matches a known CVE, and a penetration tester later confirms the issue by manual validation or controlled exploit. Because the vulnerability actually exists and the detection is accurate, this represents the scanner working as intended rather than producing a false alarm. The term false positive is reserved for a report that does not correspond to any real weakness.
- ✗
A vulnerability that is exploited during the test.
Why it's wrong here
Exploiting a vulnerability during the test is an active attack phase, not a scanner error classification. If an exploit succeeds against a reported finding, that action confirms the finding is a true positive, because the vulnerability has been proven to be exploitable in the assessed environment. If the exploit fails, the finding may be a false positive, but the act of exploitation itself is not the definition of a false positive; exploitation is verification and can also yield false negatives when the scanner missed a real issue that the tester subsequently exploits. In penetration testing terminology, a false positive is specifically a detection mistake made by the scanner, independent of whether it was later attacked.
- ✓
A vulnerability that the scanner reports but does not actually exist.
Why this is correct
This is the definition of a false positive: the scanner generates an alert based on a signature, version banner, or service fingerprint, but the claimed vulnerability does not actually exist in the target environment. For example, an automated scanner might flag a TLS configuration or an installed software version as vulnerable because the detection logic matches a generic CVE, even though the vendor has backported security patches or the vulnerable component is disabled. Such erroneous reports consume remediation resources and cause confusion, which is why manual verification is required before acting on scan results.
- ✗
A vulnerability that exists but the scanner fails to detect it.
Why it's wrong here
A vulnerability that exists but the scanner fails to detect is a false negative, the complementary error to a false positive. The scanner may have an outdated signature database, lack a plugin for the specific software, or the target may evade detection through obfuscation or custom protocols, so the real flaw goes unreported. This is dangerous because security teams assume the network is clean when actual exploitable weaknesses remain. It is not a false positive, because the problem is the scanner's omission, not an incorrect alert.
Go deeper
Related to this question
Learn chapter
Active Scanning and Enumeration
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
False positive
A false positive is an alert or result that indicates a security threat or vulnerability exists when in fact there is no real issue.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.