Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: A security auditor is reviewing the results of a…

A security auditor is reviewing the results of a recently completed internal vulnerability scan. The scan report shows several hosts with the same vulnerability. Which of the following actions should the auditor take FIRST?

⚠ Common exam trap

A common mix-up: candidates assume automated scan results are always accurate and jump to remediation (Option B) or isolation (Option C), failing to recognize that the first step in the assessment process is to validate findings to avoid acting on false positives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Manually verify the vulnerability on a sample of affected hosts.

The auditor must first manually verify the vulnerability on a sample of affected hosts because automated vulnerability scans can produce false positives due to factors like incomplete banner grabbing, outdated plugin signatures, or network-level interference. Confirming the finding ensures that subsequent remediation efforts are based on accurate, validated data, preventing wasted resources on non-existent issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Manually verify the vulnerability on a sample of affected hosts.

    Why this is correct

    An auditor's primary role includes validating findings to ensure accuracy and reduce the risk of acting on erroneous information. Manually verifying a sample of affected hosts directly confirms the vulnerability's existence and helps differentiate between actual threats and potential false positives from automated scans. This targeted approach ensures that subsequent remediation efforts are focused on legitimate security concerns, preventing unnecessary resource expenditure and potential system disruption.

  • Immediately apply patches to all affected hosts.

    Why it's wrong here

    Applying patches without first confirming the vulnerability's existence can lead to significant operational issues and wasted resources. If the initial scan result is a false positive, deploying an unnecessary patch could introduce new bugs, cause system instability, or lead to unexpected downtime. A robust change management process, which is essential for maintaining system integrity, mandates thorough validation before implementing any system modifications.

  • Remove the hosts from the network until the vulnerability is resolved.

    Why it's wrong here

    Removing hosts from the network is a highly disruptive and extreme measure that should be reserved for confirmed, critical vulnerabilities posing an immediate and severe risk to the organization. Implementing such an action without verifying the finding can cause substantial business interruption, impact service availability, and incur unnecessary operational costs. This response is disproportionate to an unconfirmed scan result and should only be considered after proper risk assessment and validation.

  • Re-run the scan with a different scanner.

    Why it's wrong here

    Simply re-running the scan with a different tool does not directly confirm the initial finding or address the potential for false positives inherent in automated scanning. While different scanners may offer varied detection capabilities or identify new issues, this action primarily introduces another data point rather than validating the original report. It delays the crucial verification step needed to ascertain the true state of the vulnerability and does not provide definitive proof for the initial finding.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.