What Conclusion Should an Analyst Draw From a Validated Telnet Scan?
After reviewing the following vulnerability scanning report: A security analyst performs the following test: Which of the following would the security analyst conclude for this reported vulnerability? -
- 
Community Votes
58% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question evaluates your ability to differentiate between a genuine residual risk and an inaccurate scanner signature, with the common trap being the misapplication of compensating control logic to a directly contradicted finding.
This question tests the distinction between false positives, noise, and compensating controls during vulnerability validation. While Telnet is inherently insecure, community consensus and official scoring classify this as a false positive because the manual test directly disproves the scanner's assumption that the service operates without encryption.
The most frequent incorrect choice is D (Compensating controls exist). Candidates select this because they correctly recognize that Telnet is fundamentally flawed by design, leading them to believe encryption merely mitigates rather than eliminates the issue. However, this overlooks that the scanner's specific claim of inherent insecurity was factually disproven by the verification step, which aligns with the definition of a false positive in exam contexts.
Community Discussion (36 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Scenario
The initial vulnerability scan flagged the Telnet service on 192.168.14.6 as using an insecure network protocol. By default, Telnet transmits all data, including credentials, in plaintext, making it highly vulnerable to eavesdropping. To validate this finding, the analyst runs an Nmap script (telnet-encryption) which explicitly reports that the Telnet server supports encryption.Why Option A Is Correct
A false positive occurs when a scanning tool incorrectly identifies a vulnerability based on hardcoded assumptions, outdated signatures, or lack of deep inspection capabilities. In this case, the scanner assumed the Telnet implementation was completely unencrypted. The manual verification directly contradicts that assumption by proving the server actually supports encryption. As noted by community experts, the scanner's premise was invalidated by the test results, meaning the original alert was inaccurate for this specific host configuration [1][5][10]. Therefore, the analyst correctly concludes it is a false positive.Why Option D Is the Primary Trap
Many candidates argue for compensating controls because they know Telnet is insecure by design and believe encryption only mitigates risk rather than fixing it [4][6][11]. While technically true in a broad security architecture sense, CompTIA exams focus on the precise wording of the scanner's finding versus the verification result. Since the scanner flagged the lack of encryption as the vulnerability, and the test proves encryption exists, the finding itself is proven false. Compensating controls apply when the vulnerability is confirmed but another mechanism reduces the risk; here, the vulnerability claim was debunked.Why Options B and C Are Incorrect
A rescan is required only if the initial test fails, times out, or yields inconclusive results. Since the analyst successfully ran a targeted verification script, no rescan is needed. Noise refers to recurring, irrelevant, or unactionable alerts that do not impact security posture. Because this finding was actively investigated and resolved through verification, it does not qualify as noise.Official Reference
- CompTIA Security+ SY0-701 Objective 4.3: Perform vulnerability scans and interpret results.
- Nmap Network Scanner Documentation: telnet-encryption Script
- RFC 2945: TELNET Encryption Specification
Exam Strategy
When faced with vulnerability validation questions, carefully compare the scanner's exact claim against the manual test's output. If the test proves the scanner's specific technical assumption wrong, classify it as a false positive; if the test confirms the flaw but shows an additional safeguard, classify it as a compensating control. Always prioritize the explicit evidence over general protocol knowledge.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →
telnet-encryptionscript shows that the Telnet server supports encryption. Given that Telnet is typically insecure due to lack of encryption, the presence of encryption support indicates that the reported vulnerability might not be accurate. Therefore, the security analyst would conclude that the reported vulnerability is a false positive.