GSEC Practice Question: Vulnerability Scanning and Penetration Testing
A vulnerability scan of a production web server reports a critical remote code execution vulnerability, but the system administrator insists the server is fully patched. The scanner used only unauthenticated checks. Which step should the security analyst take FIRST to resolve the discrepancy?
⚠ Common exam trap
The trap here is trusting either the unauthenticated scan or the administrator's assurance without independent verification, when the real answer lies in authenticated, host-level validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform an authenticated scan and manually verify the vulnerability on the host
Unauthenticated scans infer vulnerabilities from banners and service responses, which can produce false positives. To resolve the conflict between the scanner and the administrator, the analyst should perform an authenticated scan that reads installed package versions and manually verify the issue on the host. This provides definitive evidence and avoids both unnecessary downtime and premature closure of a critical finding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rescan the server with a different unauthenticated scanner to compare results
Why it's wrong here
Using another unauthenticated scanner may provide a second opinion, but it still relies on remote inference and can produce the same false positive. It does not definitively confirm patch status. Authenticated scanning or manual host verification is needed to resolve the discrepancy accurately, so this step alone is insufficient.
- ✗
Immediately take the server offline to prevent exploitation
Why it's wrong here
Taking a production server offline based on an unconfirmed unauthenticated finding is premature and disruptive. The finding may be a false positive caused by banner grabbing or version inference. The analyst should first validate the result through authenticated scanning or manual verification before recommending outage, which could cause unnecessary business impact.
- ✗
Accept the administrator's statement and close the finding as a false positive
Why it's wrong here
Closing the finding solely because the administrator disagrees ignores the possibility that the server is genuinely vulnerable or that a patch did not apply correctly. Proper validation is required before dismissing a critical finding. Accepting the statement without evidence could leave a serious vulnerability unaddressed and undermine the integrity of the vulnerability management process.
- ✓
Perform an authenticated scan and manually verify the vulnerability on the host
Why this is correct
Authenticated scanning reads the actual installed package versions and patch levels, providing far more accurate results than banner-based inference. Manually verifying the vulnerability on the host confirms whether the issue truly exists. This approach resolves the discrepancy between the scanner's report and the administrator's claim without causing unnecessary disruption or acting on a possible false positive.
Visual reference
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.