What Term Describes a Vulnerability Flagged by a Scanner But Not Present?

After conducting a vulnerability scan, a systems administrator notices that one of the identified vulnerabilities is not present on the systems that were scanned. Which of the following describes this example?

  1. False positive Source Reference Answer
  2. False negative
  3. True positive
  4. True negative

Community Votes

A
50%
B
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question evaluates precise reading of scanning terminology, with the primary trap being the misinterpretation of 'identified' as ground truth rather than the scanner's initial alert.

This question tests your ability to distinguish between vulnerability scanning result types by comparing scanner output against actual system state. While the community vote is split, the scenario clearly describes a tool incorrectly reporting a non-existent flaw, making False positive the correct answer.

Candidates frequently select False negative by mistakenly assuming the scanner failed to detect a real issue, overlooking that the prompt explicitly states the vulnerability was already flagged by the scan but proven absent upon verification.

Community Discussion (9 comments)

SAM0678 👍 3 Selected: B
Its a false negative
mejestique 👍 1 Selected: B
Its a false negative
tomahawk117 👍 2 Selected: B
This one is a false negative. Why? A known vulnerability has been found but the scanner failed to see it. False Positive means the scanner incorrectly identified a vulnerability
test_arrow 👍 4 Selected: A
the vulnerability was NOT present after the scan indicates a false positive
TmNvrWts 👍 3 Selected: A
The correct answer is: A. False positive Explanation: A false positive occurs when a security system incorrectly flags a vulnerability or threat that does not actually exist on the system. In this case, the vulnerability scan reported an issue, but upon further investigation, the administrator confirmed that the vulnerability is not present. Why not the other options? B. False negative – This would mean a vulnerability is present but was not detected, which is the opposite of what happened here. C. True positive – This would mean the vulnerability was correctly identified and is actually present on the system. D. True negative – This would mean the system was correctly identified as not having the vulnerability, but in this case, the scan incorrectly reported it.
ijia_Ai0823 👍 2 Selected: B
B. False negative. Because it is an "identified" vulnerabilities but not reported by a scan.
rrynzon 👍 3
False Positive - Normal or expected activity is incorrectly identified as abnormal or unexpected. False Negative - Abnormal or unexpected activity is incorrectly identified as normal or expected. Therefore, B is the correct answer.
jafyyy 👍 2
A. False Positive - an alert for an event that is not a threat.
qacollin 👍 1 Selected: A
A. GPT

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Scanning Result Matrix

The foundation of this question lies in mapping the scanner's output against the actual system state. The prompt states that a vulnerability was 'identified' during the scan, meaning the tool generated an alert or report indicating its presence. However, when the administrator verified the systems, they confirmed the vulnerability was not present. This mismatch—where the detection tool reports an issue that does not actually exist—is the textbook definition of a false positive.

Why Option A is Correct

A false positive occurs when a security control or scanning tool incorrectly flags benign activity or a non-existent threat as malicious/vulnerable. In vulnerability management, scanners often trigger false positives due to outdated signatures, configuration quirks, or overlapping service versions. Since the scan reported a flaw that wasn't actually there, option A perfectly aligns with the scenario.

Why Other Options Are Incorrect

  • False negative (Option B): This occurs when a real vulnerability exists on the system, but the scanner fails to detect it. The scenario explicitly states the opposite: the scanner did identify it, but it wasn't actually there.
  • True positive (Option C): This would mean the scanner correctly identified a vulnerability that actually exists on the system. Verification would confirm the flaw is present.
  • True negative (Option D): This indicates the scanner correctly found no issues, and indeed, no vulnerabilities exist. The scenario involves a flagged finding, so this does not apply.

Community Insights & Exam Tips

The community vote is split 50/50, largely due to ambiguous phrasing in the question. Some candidates interpret 'identified vulnerabilities' as what the admin found later, reversing the logic. However, in certification contexts, 'identified' in the context of a scan report always refers to the tool's initial findings. As noted in comment [5], confirming a flagged item doesn't exist directly points to a false positive. Always construct a quick 2x2 matrix during the exam: Scanner Says Yes/No vs. Reality Is Yes/No. This eliminates guesswork and ensures accuracy under time pressure.

Official Reference

  • CompTIA Security+ SY0-701 Objective 4.4 (Evaluate Application, Host, and Network Security Tools)
  • NIST Special Publication 800-115, Technical Guide to Information Security Testing and Assessment
  • Cisco Cybersecurity Operations Fundamentals: Vulnerability Management Guidelines

Exam Strategy

When analyzing vulnerability scanning questions, immediately separate the tool's report from ground-truth verification. If the tool flags something that isn't actually there, it's a false positive; if it misses something that is there, it's a false negative. Creating a quick mental matrix prevents falling for trick wording like 'identified' or 'reported' and saves valuable exam time.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide