Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

While performing vulnerability scanning with Nessus, a penetration tester notices that several high-severity vulnerabilities are reported for a web server, but manual verification shows the server is not vulnerable. What is the MOST likely cause of this discrepancy?

⚠ Common exam trap

A common mix-up: candidates assume high-severity findings must be real, or they confuse false positives with missed vulnerabilities due to authentication or plugin issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The scanner is reporting false positives due to inaccurate version detection

Nessus performs version-based detection by analyzing server banners and HTTP response headers. If the web server's software version string is outdated or misconfigured, the scanner may flag vulnerabilities that do not actually exist in the patched or custom-compiled version. This is a classic false positive scenario where the scanner relies on version matching rather than actual exploit verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The scanner used unauthenticated scans, missing the actual vulnerabilities

    Why it's wrong here

    Unauthenticated scans lack the necessary credentials to enumerate missing patches or configuration weaknesses, so they often report fewer findings rather than extra ones. The absence of authentication means the scanner can only see exposed services, and if a vulnerability requires a logged-in state, it will be missed—producing false negatives. This cannot explain false positives, which are erroneous positive reports.

  • ✗

    The scanner configuration excluded necessary plugins for accurate testing

    Why it's wrong here

    Excluding plugins from a scanning configuration narrows the scope of security checks performed, directly reducing the chances of detecting real vulnerabilities. This exclusion causes false negatives because no test is executed for those specific weaknesses, not false positives. False positives arise from incorrect test logic or false assumptions, not from skipping checks.

  • ✗

    The target server is behind a load balancer that modifies responses

    Why it's wrong here

    A load balancer that modifies responses can route traffic to different backend servers or alter headers, but this typically affects request distribution and session persistence rather than the scanner's vulnerability matching logic. While unusual response patterns might confuse some fingerprinting, the most common source of false positives remains the scanner's version detection heuristics. Therefore, load balancing is an unlikely and less direct cause of spurious findings.

  • ✓

    The scanner is reporting false positives due to inaccurate version detection

    Why this is correct

    Version-based detection is a heuristic where the scanner matches a service's banner or fingerprint against a vulnerability database; if the version string is parsed incorrectly or the banner is outdated, false positives occur. For example, a web server with a backported security patch may still display an old version number, leading the scanner to flag a vulnerability that is not actually present. This is a well-known limitation of unauthenticated scanning and a common cause of erroneous positive reports.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.