PT0-002 Reconnaissance and Enumeration Practice Question
While performing vulnerability scanning with Nessus, a penetration tester notices that several high-severity vulnerabilities are reported for a web server, but manual verification shows the server is not vulnerable. What is the MOST likely cause of this discrepancy?
⚠ Common exam trap
A common mix-up: candidates assume high-severity findings must be real, or they confuse false positives with missed vulnerabilities due to authentication or plugin issues.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The scanner is reporting false positives due to inaccurate version detection
Nessus performs version-based detection by analyzing server banners and HTTP response headers. If the web server's software version string is outdated or misconfigured, the scanner may flag vulnerabilities that do not actually exist in the patched or custom-compiled version. This is a classic false positive scenario where the scanner relies on version matching rather than actual exploit verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The scanner used unauthenticated scans, missing the actual vulnerabilities
Why it's wrong here
Unauthenticated scans lack the necessary credentials to enumerate missing patches or configuration weaknesses, so they often report fewer findings rather than extra ones. The absence of authentication means the scanner can only see exposed services, and if a vulnerability requires a logged-in state, it will be missed—producing false negatives. This cannot explain false positives, which are erroneous positive reports.
- ✗
The scanner configuration excluded necessary plugins for accurate testing
Why it's wrong here
Excluding plugins from a scanning configuration narrows the scope of security checks performed, directly reducing the chances of detecting real vulnerabilities. This exclusion causes false negatives because no test is executed for those specific weaknesses, not false positives. False positives arise from incorrect test logic or false assumptions, not from skipping checks.
- ✗
The target server is behind a load balancer that modifies responses
Why it's wrong here
A load balancer that modifies responses can route traffic to different backend servers or alter headers, but this typically affects request distribution and session persistence rather than the scanner's vulnerability matching logic. While unusual response patterns might confuse some fingerprinting, the most common source of false positives remains the scanner's version detection heuristics. Therefore, load balancing is an unlikely and less direct cause of spurious findings.
- ✓
The scanner is reporting false positives due to inaccurate version detection
Why this is correct
Version-based detection is a heuristic where the scanner matches a service's banner or fingerprint against a vulnerability database; if the version string is parsed incorrectly or the banner is outdated, false positives occur. For example, a web server with a backported security patch may still display an old version number, leading the scanner to flag a vulnerability that is not actually present. This is a well-known limitation of unauthenticated scanning and a common cause of erroneous positive reports.
Go deeper
Related to this question
Learn chapter
Nmap Scanning Techniques
Key term
False positive
A false positive is an alert or result that indicates a security threat or vulnerability exists when in fact there is no real issue.
Key term
Nessus
Nessus is a vulnerability scanner that automatically identifies security weaknesses, missing patches, and misconfigurations in computer systems and networks.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.