Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A vulnerability management team is scanning a network. Which THREE factors should be considered to minimize false positives?

⚠ Common exam trap

A common misconception is that scanning during peak hours yields more accurate results, when in fact it degrades scan reliability and increases false positives due to network load and timeouts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tuning the scanner based on the environment

Option C is correct because tuning the scanner to the specific environment—adjusting plugin sets, port ranges, timing templates, and severity thresholds—reduces noise from irrelevant checks and mismatched assumptions, which directly lowers false positives. Option D is correct because authenticated (credentialed) scans let the scanner read actual patch levels, registry keys, and installed software instead of inferring vulnerabilities from banners or version strings, eliminating many false positives caused by backported patches or obscured services. Option E is correct because manually verifying findings (for example, confirming a suspected open port with netstat or a service banner with a targeted probe) validates scanner output before it is reported, catching false positives that automated logic cannot resolve. Option A is not correct because scanning only during peak hours does not reduce false positives and can actually increase them through timeouts and dropped packets under load. Option B is not correct because default scan profiles are generic and often produce more false positives, since they are not tailored to the target environment's operating systems, applications, or network topology.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scanning only during peak hours

    Why it's wrong here

    Peak-hour scanning increases contention and timeouts, which generate false positives rather than reduce them; scanning windows should instead be chosen to balance load and coverage. Off-peak scheduling is genuinely useful for minimising production impact during intensive authenticated scans, but it does not address false-positive accuracy.

  • ✗

    Using default scan profiles

    Why it's wrong here

    Default scan profiles apply broad plugin sets and generic timing, producing false positives on non-standard services; tuning plugin selection, credentials and exclusions reduces them. Defaults are tempting for speed of setup, and would be correct for an initial broad discovery sweep rather than accurate vulnerability reporting.

  • ✓

    Tuning the scanner based on the environment

    Why this is correct

    Scanner signatures and severity thresholds are generic by default, so tuning them to the actual operating systems, applications and network topology removes checks that do not apply. This eliminates environment-specific false positives before they reach analysts.

  • ✓

    Performing authenticated scans

    Why this is correct

    Authenticated scans log into targets and read installed patch levels, registry keys and package versions directly, rather than inferring them from banner responses. This removes the guesswork that generates false positives when services are misidentified or version banners are inaccurate.

  • ✓

    Manually verifying results

    Why this is correct

    Manually verifying results lets analysts confirm each suspected vulnerability before it is reported, filtering out scanner misidentifications. This directly minimises false positives, satisfying the stem's constraint, because human inspection distinguishes genuine exposures from benign configurations that automated signatures wrongly flag.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.