What Conclusion Should an Analyst Draw From a Validated Telnet Scan?

After reviewing the following vulnerability scanning report: A security analyst performs the following test: Which of the following would the security analyst conclude for this reported vulnerability? - image - image

  1. It is a false positive. Source Reference Answer
  2. A rescan is required.
  3. It is considered noise.
  4. Compensating controls exist.

Community Votes

A
58%
D
42%

58% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question evaluates your ability to differentiate between a genuine residual risk and an inaccurate scanner signature, with the common trap being the misapplication of compensating control logic to a directly contradicted finding.

This question tests the distinction between false positives, noise, and compensating controls during vulnerability validation. While Telnet is inherently insecure, community consensus and official scoring classify this as a false positive because the manual test directly disproves the scanner's assumption that the service operates without encryption.

The most frequent incorrect choice is D (Compensating controls exist). Candidates select this because they correctly recognize that Telnet is fundamentally flawed by design, leading them to believe encryption merely mitigates rather than eliminates the issue. However, this overlooks that the scanner's specific claim of inherent insecurity was factually disproven by the verification step, which aligns with the definition of a false positive in exam contexts.

Community Discussion (36 comments)

mr_reyes 👍 17 Selected: A
False Positive: A false positive occurs when a vulnerability scanner incorrectly identifies a vulnerability that doesn’t actually exist. In this case, the initial vulnerability report flagged the use of an insecure network protocol (Telnet) on the server at 192.168.14.6. However, the follow-up test using Nmap with the telnet-encryption script revealed that the Telnet server supports encryption. Since encryption enhances security, the initial report was incorrect. Therefore, the conclusion is that the initial report was a false positive.
dbrowndiver 👍 9 Selected: A
Why This Is a False Positive: 1. Understanding Telnet: General Security Issues: Telnet typically transmits data in plaintext, making it susceptible to eavesdropping and other security vulnerabilities. This is why it is often flagged in security scans. 2. Encryption Support: Security Enhancement: The presence of encryption changes the security profile of Telnet. If encryption is supported and properly implemented, the transmission of data is secure, counteracting the usual vulnerabilities associated with Telnet. 3. Initial Assessment: Misinterpretation: The initial report indicated a vulnerability due to a general assumption that Telnet is insecure, without verifying the specific configuration that includes encryption. 4. Conclusion: False Positive: Since the Telnet server supports encryption, the assumption of insecurity was incorrect. The vulnerability scanner flagged an issue based on typical characteristics rather than the actual configuration of this specific Telnet implementation.
Linas312 👍 1 Selected: A
Horrible question, Telnet is an insecure protocol by design, encryption or no encyption.. period Nmap scan only confirms that it supports encryption, means nothing really, should look to implement something more secure like SSH or jumpbox.. if that's what is meant by D. that would be the answer however the "Theory question" answer here is probably A.
Commando9800 👍 1 Selected: D
D. Compensating controls exist. My explaining: Vulnerability detected is : Use of an insecure network protocol Having an encryption doesn't change the fact that Telnet is an insecure protocol The answer would be False Positive if the vulnerability detected was lack of encryption In the end Comptia decide the ultimate truth in this exam so
testpan 👍 1 Selected: A
According to ChatGPT , it says origin report is "Use of an insecure network protocol", but when using nmap to test , it discover "Telnet server supports encryption" , so it means this is contradict to the origin report, so this is False Positive
Russell15 👍 3 Selected: D
False positive (A) would mean Telnet was incorrectly flagged as insecure—but Telnet is still a risk by default. Compensating controls (D) is correct because encryption helps mitigate the risk, but the risk still exists.
Catalyst33 👍 1 Selected: D
Adding encryption to telnet does not make it as secure as SSH which the scanner would not pick up as a vulnerability. Sure you have encryption, but what about authentication?
Rackup 👍 1 Selected: A
The vulnerability scanner flagged the use of Telnet as an insecure network protocol, which is typically true because Telnet is unencrypted. However, the security analyst ran a test using Nmap and found that the Telnet server supports encryption. This suggests that the reported vulnerability was a false positive. Since the server supports encryption, the actual risk is mitigated, and the vulnerability scanning report is inaccurate in this context.
WTD34 👍 1 Selected: D
The question is asking "what can be concluded". We know that telnet is unsafe by default. We also know that there is an option for encryption as said by the last line "telnet server supports encryption". Thus the answer must be that we can conclude Compensating Controls Exist. answer is D
limatsao 👍 1 Selected: A
The correct answer is: A. It is a false positive. Explanation: The vulnerability scan initially flagged the use of Telnet as insecure because Telnet traditionally sends data, including credentials, in plaintext. However, the nmap test with the --script telnet-encryption option shows that the Telnet server supports encryption, which mitigates the reported risk. This means the vulnerability scanner flagged the issue without accounting for the encryption capability, leading to a false positive. Why the other options are incorrect: B. A rescan is required: The manual test using nmap already confirmed that encryption is supported, so a rescan is unnecessary. C. It is considered noise: Noise refers to irrelevant or unimportant alerts. This finding was important to verify but is ultimately a false positive, not noise. D. Compensating controls exist: The encryption supported by the Telnet server is not a compensating control but a direct mitigation of the issue.
Storcaks 👍 2 Selected: D
The scan only reports that the telnet server SUPPORTS encryption, but there's no information that state that it is required to use encryption by a client. A client that doesn't know the server supports encryption will most likely use default settings without it. Unlike SSH which is always encrypted by default. Telnet itself is inherently insecure just like FTP is. With this in mind the only choice that makes sense is D.
Anyio 👍 1 Selected: A
By the way, this is a better use case of compensating controls: An organization disabled unneeded services and placed a firewall in front of a business-critical legacy system.
Anyio 👍 1 Selected: A
The Answer is A: If the only issue that makes Telnet unsafe is because Telnet traditionally uses unencrypted communication, because it now clearly shows that it has been taken care of. The Answer is D: If there are other reasons not to use telnet besides it being unencrypted. If you can mention any other reasons or vulnerabilities then D will be the answer as encrypting it will just be a compensating solution.
1022572 👍 3 Selected: D
The security scan shows telnet port as open and so did the NMAP scan. It is not a false positive A rescan is not required It is not noise D. Compensating Controls is the only correct answer.
41c27e6 👍 2 Selected: D
Impossible to be A, here is why: Telnet iteself is ALWAYS unencrypted. So, the vulnerability indentified is TRUE. However, there are techinques to support Telnet security and data encryption (like VPN).
darpanne 👍 2 Selected: D
Most vulnerability scanners (e.g., Nessus, Qualys, OpenVAS) flag Telnet as a vulnerability by default because it is inherently insecure, transmitting data in plaintext. Even with encryption enabled, Telnet remains risky compared to alternatives like SSH due to: Lack of MFA and Kerberos support, No data integrity checks, Susceptibility to brute-force attacks, Absence of session protection. If encryption exists: Modern scanners may detect it and lower the severity but will still warn about Telnet use since the protocol itself is outdated and insecure. Conclusion: Security professionals consider Telnet deprecated and risky, regardless of encryption. Thus, it is not a false positive, and D (compensating controls exist) is correct here.
AriGarcia 👍 2 Selected: D
The command nmap -p 23 192.168.14.6 --script telnet-encryption performs the following actions: scans the specified IP address for an open Telnet port (port 23) and then uses the telnet-encryption script to determine if the Telnet server supports encryption, which could indicate whether the server might be vulnerable to certain types of attacks if the encryption is not properly implemented. Since telnet is now encrypted. A compensating control exists (D)
Fagann 👍 1 Selected: A
The vulnerability scanning report initially flags the Telnet service as using an insecure protocol. Traditionally, Telnet sends data, including credentials, in cleartext, which makes it inherently insecure when compared to encrypted protocols like SSH. However, the security analyst's follow-up test using Nmap with the --script telnet-encryption option reveals that the Telnet server actually supports encryption. This means that the Telnet service in question is not transmitting data in cleartext as a standard Telnet service would. So clearly it is false positive.
Find24 👍 1 Selected: A
I thought D at first but now I believe it is A and here is why. The scan just picks up on Telnet which is not secure. The command ...telnet-encryption, was ran to see if encryption was enabled. It is enabled so therefore it is secure. The analyst didn't enable it or change anything but is now aware that it is safe and therefore a false positive.
dC_Furious 👍 2 Selected: D
I think Compensating Control exist might acrually be the right answear, the Vulnerability scan has correctly identified the vulnerability in this case, port 23 is open, the fact that there is a compensating control doesn't make it a false positive. What do you think?
3dk1 👍 1 Selected: A
Yes, compensating controls probably do exist here, however, the end result is that it IS a false positive.
BevMe 👍 2 Selected: D
I think D may be the better answer. The presence of a Telnet server, even with support for encryption, indicates a vulnerability due to the potential risks associated with using Telnet in general. While the encryption feature provides a compensating control, it does not negate the fact that using Telnet is inherently less secure compared to alternatives like SSH.
Netri 👍 1 Selected: A
The security analyst would most likely conclude: A. It is a false positive. Explanation: The vulnerability report flagged the Telnet service as insecure because Telnet traditionally uses unencrypted communication, which is considered insecure. However, the analyst performed a manual test using Nmap and discovered that the Telnet server supports encryption, which contradicts the original report. Since the service supports encryption, the vulnerability related to insecure communication (typically associated with Telnet) is not valid, meaning the original finding in the report is incorrect. Thus, this situation represents a false positive.
AriGarcia 👍 1
A) It's a false positive Here's why: The vulnerability report initially flagged the use of an insecure network protocol, Telnet, which by default does not support encryption. However, the analyst performed an Nmap scan using the telnet-encryption script, which showed that the Telnet server does support encryption. Thus, since encryption is supported, the vulnerability flagged as "insecure" can be considered a false positive because the Telnet server is using secure practices.
Ty13 👍 3 Selected: A
Another garbage question. It's technically a false positive BECAUSE compensating controls exist.
Twphill 👍 2 Selected: D
It is not a false positive because it correctly identified a vulnerability. However, compensating controls exist to mitigate this vulnerability.
Dakshdabas 👍 1 Selected: B
B. Rescan is required In pointing out that the nmap scan result shows that the Telnet server "supports encryption," but it does not confirm that encryption is actively being used. It simply indicates that the server has the capability to support encryption, but whether or not it's actually enforced during connections is another matter. Given this clarification, the best course of action for the security analyst would likely be B. A rescan is required. Explanation: Since the scan result only shows that the Telnet server supports encryption, but does not confirm that encryption is enforced, a rescan or further testing should be conducted to determine whether: Encryption is actually being used for all Telnet sessions. There is a configuration issue where encryption is supported but not enforced. The rescan should focus on verifying if encryption is mandatory for Telnet connections. If it's not, the vulnerability remains valid and should be addressed.
nyyankee718 👍 1 Selected: D
"supports encryption"
a4e15bd 👍 2
I am going to change my answer to A. False positive, because the initial report flagged Telnet as insecure, but the subsequent test showed that encryption which addresses the vulnerability is being used. This indicates the vulnerability was incorrectly reported. So, that makes it a false positive.
scoobysnack209 👍 1
The answer is D: Disable port 23 Telnet (unencrypted) and enable SSH port 22 (encrypted connection)
EfaChux 👍 2 Selected: D
Telnet supports encryption but its currently not encrypted, which means there's a vulnerability. Hence there needs to be compensating controls. D is the answer
Etc_Shadow28000 👍 1 Selected: A
A. It is a false positive. The initial vulnerability scan reported that the use of Telnet (an insecure network protocol) is a high severity issue. However, the follow-up nmap scan with the telnet-encryption script shows that the Telnet server supports encryption. Given that Telnet is typically insecure due to lack of encryption, the presence of encryption support indicates that the reported vulnerability might not be accurate. Therefore, the security analyst would conclude that the reported vulnerability is a false positive.
f26ddcd 👍 1 Selected: A
It is FP
Boats 👍 3 Selected: D
Telnet transmits in clear to text. In order to keep that from happing you have to have a compensating control. There for you encrypt it.
SHADTECH123 👍 2 Selected: A
Here's the reasoning: The initial vulnerability report indicated a high severity issue due to the use of an insecure network protocol (Telnet). However, the follow-up scan using nmap with the telnet-encryption script showed that the Telnet server supports encryption. This means that while the default perception of Telnet is that it is insecure, the particular Telnet service in question has encryption enabled, mitigating the primary security concern associated with Telnet. Hence, the initial report can be considered a false positive because the Telnet service in question does not suffer from the typical vulnerability of using an insecure protocol.
AutoroTink 👍 3 Selected: D
The security analyst used the Nmap command with a specific script to test the Telnet service on a server. Telnet is traditionally known for transmitting data in plaintext, but the result of nmap states that "this time", telnet supports encryption. (hurray!) Nmap: This is a network scanning tool that can discover devices and services on a computer network. Nmap results: PORT 23/tcp: The specific port (23) for TCP is open. STATE open: The state of the port is open, meaning it is actively accepting connections. SERVICE telnet: The service running on this port is Telnet. REASON syn-ack: This indicates that the port is open because the server responded with a SYN-ACK packet during the TCP handshake. | telnet encryption:: This is the result from the telnet-encryption script. |_ Telnet server supports encryption: The underscore indicates the result of the script, confirming that the Telnet server supports encryption.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Scenario

The initial vulnerability scan flagged the Telnet service on 192.168.14.6 as using an insecure network protocol. By default, Telnet transmits all data, including credentials, in plaintext, making it highly vulnerable to eavesdropping. To validate this finding, the analyst runs an Nmap script (telnet-encryption) which explicitly reports that the Telnet server supports encryption.

Why Option A Is Correct

A false positive occurs when a scanning tool incorrectly identifies a vulnerability based on hardcoded assumptions, outdated signatures, or lack of deep inspection capabilities. In this case, the scanner assumed the Telnet implementation was completely unencrypted. The manual verification directly contradicts that assumption by proving the server actually supports encryption. As noted by community experts, the scanner's premise was invalidated by the test results, meaning the original alert was inaccurate for this specific host configuration [1][5][10]. Therefore, the analyst correctly concludes it is a false positive.

Why Option D Is the Primary Trap

Many candidates argue for compensating controls because they know Telnet is insecure by design and believe encryption only mitigates risk rather than fixing it [4][6][11]. While technically true in a broad security architecture sense, CompTIA exams focus on the precise wording of the scanner's finding versus the verification result. Since the scanner flagged the lack of encryption as the vulnerability, and the test proves encryption exists, the finding itself is proven false. Compensating controls apply when the vulnerability is confirmed but another mechanism reduces the risk; here, the vulnerability claim was debunked.

Why Options B and C Are Incorrect

A rescan is required only if the initial test fails, times out, or yields inconclusive results. Since the analyst successfully ran a targeted verification script, no rescan is needed. Noise refers to recurring, irrelevant, or unactionable alerts that do not impact security posture. Because this finding was actively investigated and resolved through verification, it does not qualify as noise.

Official Reference

  • CompTIA Security+ SY0-701 Objective 4.3: Perform vulnerability scans and interpret results.
  • Nmap Network Scanner Documentation: telnet-encryption Script
  • RFC 2945: TELNET Encryption Specification

Exam Strategy

When faced with vulnerability validation questions, carefully compare the scanner's exact claim against the manual test's output. If the test proves the scanner's specific technical assumption wrong, classify it as a false positive; if the test confirms the flaw but shows an additional safeguard, classify it as a compensating control. Always prioritize the explicit evidence over general protocol knowledge.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide