PT0-002 Reconnaissance and Enumeration Practice Question
While performing vulnerability scanning, a penetration tester runs a Nessus scan against a web server. The report shows a 'critical' finding, but after manual verification, the tester determines the service is not actually vulnerable. This scenario best describes:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A false positive
A false positive is when a scanner reports a vulnerability that does not actually exist. Penetration testers must verify scanner findings to avoid reporting false positives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A false negative
Why it's wrong here
A false negative occurs when a scanner fails to identify a vulnerability that actually exists, meaning no alert is generated for a real security gap. In this scenario, the scanner produced an alert, so the issue is not one of omission but of incorrect reporting. Thus, this term does not describe the situation.
- ✗
A configuration error
Why it's wrong here
A configuration error might have caused the scanner to flag a non-existent issue, but it is not the classification of the alert itself. In vulnerability management terminology, an alert that is later proven invalid by manual testing is specifically called a false positive. Therefore, while a misconfiguration could be an root cause, the correct label for the incorrect alert is not 'configuration error.'
- ✓
A false positive
Why this is correct
A false positive is an alert that a vulnerability scanner generates for a condition that, upon manual verification, does not actually exist. This is precisely what happened here: the scanner flagged a weakness, but penetration testing proved it was not present. Such alerts require triage to filter noise and avoid wasting remediation effort.
- ✗
A true positive
Why it's wrong here
A true positive indicates that the scanner correctly identified a genuine vulnerability that is verified to exist. Since manual testing contradicted the scanner's finding and proved the vulnerability is absent, this is the opposite of a true positive. Therefore, labeling this result as a true positive would be factually incorrect.
Go deeper
Related to this question
Learn chapter
Nmap Scanning Techniques
Key term
False positive
A false positive is an alert or result that indicates a security threat or vulnerability exists when in fact there is no real issue.
Key term
Nessus
Nessus is a vulnerability scanner that automatically identifies security weaknesses, missing patches, and misconfigurations in computer systems and networks.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.