easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A security auditor is reviewing the results of a…
A security auditor is reviewing the results of a recently completed internal vulnerability scan. The scan report shows several hosts with the same vulnerability. Which of the following actions should the auditor take FIRST?
⚠ Common exam trap
A common mix-up: candidates assume automated scan results are always accurate and jump to remediation (Option B) or isolation (Option C), failing to recognize that the first step in the assessment process is to validate findings to avoid acting on false positives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Manually verify the vulnerability on a sample of affected hosts.
The auditor must first manually verify the vulnerability on a sample of affected hosts because automated vulnerability scans can produce false positives due to factors like incomplete banner grabbing, outdated plugin signatures, or network-level interference. Confirming the finding ensures that subsequent remediation efforts are based on accurate, validated data, preventing wasted resources on non-existent issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Manually verify the vulnerability on a sample of affected hosts.
Why this is correct
An auditor's primary role includes validating findings to ensure accuracy and reduce the risk of acting on erroneous information. Manually verifying a sample of affected hosts directly confirms the vulnerability's existence and helps differentiate between actual threats and potential false positives from automated scans. This targeted approach ensures that subsequent remediation efforts are focused on legitimate security concerns, preventing unnecessary resource expenditure and potential system disruption.
- ✗
Immediately apply patches to all affected hosts.
Why it's wrong here
Applying patches without first confirming the vulnerability's existence can lead to significant operational issues and wasted resources. If the initial scan result is a false positive, deploying an unnecessary patch could introduce new bugs, cause system instability, or lead to unexpected downtime. A robust change management process, which is essential for maintaining system integrity, mandates thorough validation before implementing any system modifications.
- ✗
Remove the hosts from the network until the vulnerability is resolved.
Why it's wrong here
Removing hosts from the network is a highly disruptive and extreme measure that should be reserved for confirmed, critical vulnerabilities posing an immediate and severe risk to the organization. Implementing such an action without verifying the finding can cause substantial business interruption, impact service availability, and incur unnecessary operational costs. This response is disproportionate to an unconfirmed scan result and should only be considered after proper risk assessment and validation.
- ✗
Re-run the scan with a different scanner.
Why it's wrong here
Simply re-running the scan with a different tool does not directly confirm the initial finding or address the potential for false positives inherent in automated scanning. While different scanners may offer varied detection capabilities or identify new issues, this action primarily introduces another data point rather than validating the original report. It delays the crucial verification step needed to ascertain the true state of the vulnerability and does not provide definitive proof for the initial finding.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.