GPEN Vulnerability Scanning Practice Question
A penetration tester is using Nmap with the NSE script 'vulners' to identify vulnerabilities on a target. The scan returns a list of CVEs for detected services, but the tester notices that some CVEs have a low confidence score. What is the MOST accurate interpretation of these low-confidence findings?
⚠ Common exam trap
The trap here is equating low confidence with false positive, when it actually means the version match is uncertain and needs verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They are potential matches based on version correlation and should be manually verified before reporting.
Low confidence in vulners output signals an approximate version-to-CVE match. Because service banners can be incomplete or versions backported, the script cannot be certain the vulnerability exists. The correct response is to treat these as potential findings and manually verify the service's exact version and patch state before reporting. This avoids both false positives and false negatives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They indicate that the CVE is not in the NVD database and is therefore invalid.
Why it's wrong here
The vulners script aggregates from multiple sources, not just NVD. A low confidence score does not mean the CVE is invalid or absent from NVD. It simply reflects the strength of the version match. Many valid CVEs might have low confidence due to version range overlap or imprecise banners. Dismissing them as invalid is incorrect.
- ✗
They indicate that the vulnerability is likely a false positive and should be ignored.
Why it's wrong here
A low confidence score does not necessarily mean false positive; it indicates the match between the detected service version and the CVE is not exact or is based on incomplete data. Ignoring them could miss real vulnerabilities. These findings warrant further investigation, not dismissal. The confidence score reflects uncertainty in the detection method, not a definitive negative.
- ✓
They are potential matches based on version correlation and should be manually verified before reporting.
Why this is correct
The vulners NSE script correlates detected service versions with CVE databases. A low confidence score means the match is approximate, often due to version string ambiguity or missing patch information. These findings are leads that require manual verification, such as checking the exact build or testing the vulnerability, before being included in a report.
- ✗
They represent vulnerabilities that require authentication to exploit and are therefore lower risk.
Why it's wrong here
The confidence score in vulners is unrelated to authentication requirements. It reflects how well the detected version matches the CVE's affected version range. A low score could still be an unauthenticated remote exploit. Assuming authentication is needed is incorrect and could lead to underestimating risk. The score is about detection certainty, not exploit prerequisites.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.