Courseiva

GSEC Practice Question: Vulnerability Scanning and Penetration Testing

A vulnerability scan of a production web server reports a critical remote code execution vulnerability, but the system administrator insists the server is fully patched. The scanner used only unauthenticated checks. Which step should the security analyst take FIRST to resolve the discrepancy?

⚠ Common exam trap

The trap here is trusting either the unauthenticated scan or the administrator's assurance without independent verification, when the real answer lies in authenticated, host-level validation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform an authenticated scan and manually verify the vulnerability on the host

Unauthenticated scans infer vulnerabilities from banners and service responses, which can produce false positives. To resolve the conflict between the scanner and the administrator, the analyst should perform an authenticated scan that reads installed package versions and manually verify the issue on the host. This provides definitive evidence and avoids both unnecessary downtime and premature closure of a critical finding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rescan the server with a different unauthenticated scanner to compare results

    Why it's wrong here

    Using another unauthenticated scanner may provide a second opinion, but it still relies on remote inference and can produce the same false positive. It does not definitively confirm patch status. Authenticated scanning or manual host verification is needed to resolve the discrepancy accurately, so this step alone is insufficient.

  • ✗

    Immediately take the server offline to prevent exploitation

    Why it's wrong here

    Taking a production server offline based on an unconfirmed unauthenticated finding is premature and disruptive. The finding may be a false positive caused by banner grabbing or version inference. The analyst should first validate the result through authenticated scanning or manual verification before recommending outage, which could cause unnecessary business impact.

  • ✗

    Accept the administrator's statement and close the finding as a false positive

    Why it's wrong here

    Closing the finding solely because the administrator disagrees ignores the possibility that the server is genuinely vulnerable or that a patch did not apply correctly. Proper validation is required before dismissing a critical finding. Accepting the statement without evidence could leave a serious vulnerability unaddressed and undermine the integrity of the vulnerability management process.

  • ✓

    Perform an authenticated scan and manually verify the vulnerability on the host

    Why this is correct

    Authenticated scanning reads the actual installed package versions and patch levels, providing far more accurate results than banner-based inference. Manually verifying the vulnerability on the host confirms whether the issue truly exists. This approach resolves the discrepancy between the scanner's report and the administrator's claim without causing unnecessary disruption or acting on a possible false positive.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.