PT0-002 Reconnaissance and Enumeration Practice Question
You are performing a vulnerability scan on a web application and notice that the scanner reports a high-severity SQL injection vulnerability. However, manual testing confirms that the input is properly sanitized. Which term best describes this situation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
False positive
A false positive occurs when a scanner incorrectly identifies a vulnerability that does not exist. This is common in automated vulnerability scanning and requires manual verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
False negative
Why it's wrong here
A false negative in a web application vulnerability scan occurs when the scanner fails to detect an actual security flaw that is present, such as a stored XSS or a known vulnerable dependency. This is the most dangerous type of error because it provides a false sense of security, leading security teams to believe the application is secure when an exploitable vulnerability remains. Unlike a false positive, it does not trigger unnecessary investigation but instead allows real risk to go unaddressed, potentially resulting in a breach.
- ✗
True positive
Why it's wrong here
A true positive means the scanner accurately identified a vulnerability that genuinely exists in the web application, such as an unpatched critical CVE or a misconfigured CORS policy. The scanner's detection logic, whether signature-based or heuristic, correctly matched the evidence of the flaw in the HTTP responses or server behavior. This is the ideal scanning outcome because it directs remediation efforts toward a real risk, though manual verification is still recommended to confirm the finding before remediation.
- ✗
Inconclusive
Why it's wrong here
An inconclusive result indicates that the scanner could not gather sufficient evidence to determine whether a vulnerability is present, often due to session expiration, multi-step authentication, or nondeterministic server responses. It is not an incorrect alert but rather an unresolved one, meaning the scanner abstains from a definitive verdict. This finding demands manual penetration testing or a re-scan under controlled conditions, distinguishing it from a false positive, which is a confident but wrong assertion of a vulnerability.
- ✓
False positive
Why this is correct
A false positive is an incorrect alert in which the scanner reports a vulnerability that does not actually exist in the web application, such as flagging a sanitized input parameter as SQL injectable. This often occurs due to heuristic detection misfires, outdated signature databases, or responses that imitate vulnerability patterns without the underlying weakness. It consumes security team time and resources on investigating and remediating non-existent issues, highlighting why every automated finding should be validated before being acted upon.
Go deeper
Related to this question
Learn chapter
XXE Injection Attacks
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
Key term
False positive
A false positive is an alert or result that indicates a security threat or vulnerability exists when in fact there is no real issue.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.