Courseiva

PT0-002 Reconnaissance and Enumeration Practice Question

You are performing a vulnerability scan on a web application and notice that the scanner reports a high-severity SQL injection vulnerability. However, manual testing confirms that the input is properly sanitized. Which term best describes this situation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

False positive

A false positive occurs when a scanner incorrectly identifies a vulnerability that does not exist. This is common in automated vulnerability scanning and requires manual verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    False negative

    Why it's wrong here

    A false negative in a web application vulnerability scan occurs when the scanner fails to detect an actual security flaw that is present, such as a stored XSS or a known vulnerable dependency. This is the most dangerous type of error because it provides a false sense of security, leading security teams to believe the application is secure when an exploitable vulnerability remains. Unlike a false positive, it does not trigger unnecessary investigation but instead allows real risk to go unaddressed, potentially resulting in a breach.

  • ✗

    True positive

    Why it's wrong here

    A true positive means the scanner accurately identified a vulnerability that genuinely exists in the web application, such as an unpatched critical CVE or a misconfigured CORS policy. The scanner's detection logic, whether signature-based or heuristic, correctly matched the evidence of the flaw in the HTTP responses or server behavior. This is the ideal scanning outcome because it directs remediation efforts toward a real risk, though manual verification is still recommended to confirm the finding before remediation.

  • ✗

    Inconclusive

    Why it's wrong here

    An inconclusive result indicates that the scanner could not gather sufficient evidence to determine whether a vulnerability is present, often due to session expiration, multi-step authentication, or nondeterministic server responses. It is not an incorrect alert but rather an unresolved one, meaning the scanner abstains from a definitive verdict. This finding demands manual penetration testing or a re-scan under controlled conditions, distinguishing it from a false positive, which is a confident but wrong assertion of a vulnerability.

  • ✓

    False positive

    Why this is correct

    A false positive is an incorrect alert in which the scanner reports a vulnerability that does not actually exist in the web application, such as flagging a sanitized input parameter as SQL injectable. This often occurs due to heuristic detection misfires, outdated signature databases, or responses that imitate vulnerability patterns without the underlying weakness. It consumes security team time and resources on investigating and remediating non-existent issues, highlighting why every automated finding should be validated before being acted upon.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.