exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 21 discussion

Actual exam question from CompTIA's PT0-002
Question #: 21
Topic #: 1
[All PT0-002 Questions]

A penetration tester completed a vulnerability scan against a web server and identified a single but severe vulnerability.
Which of the following is the BEST way to ensure this is a true positive?

  • A. Run another scanner to compare.
  • B. Perform a manual test on the server.
  • C. Check the results on the scanner.
  • D. Look for the vulnerability online.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MeisAdriano
9 months ago
Selected Answer: B
Only a manual test is the BEST way to confirm an automated/scripted test.
upvoted 1 times
...
deeden
1 year, 2 months ago
Selected Answer: C
I vote option C. Checking the result can reveal software version conflict with the actual system which could clearly identify true or false positive. This also saves time trying to exploit the vulnerability manually just to prove a point.
upvoted 1 times
...
solutionz
1 year, 9 months ago
Selected Answer: B
A true positive in vulnerability scanning means that the vulnerability really exists, and it's not a mistake or false alarm by the scanning tool. The best way to confirm a true positive is to manually test the vulnerability. By manually testing the vulnerability, the penetration tester can verify the conditions under which it occurs, understand its impact, and confirm that it's not a false positive reported by the automated scanning tool. So the correct answer to this question is: B. Perform a manual test on the server.
upvoted 4 times
...
cy_analyst
2 years, 2 months ago
Selected Answer: B
Performing a manual test on the server is the best way to confirm the vulnerability and to determine its potential impact. This will involve attempting to exploit the vulnerability to verify that it is indeed present and can be used to gain unauthorized access or perform other malicious activities. Manual testing can also help to identify any additional vulnerabilities that may have been missed by the automated scanner.
upvoted 3 times
...
RRabbit_111
2 years, 3 months ago
Selected Answer: B
B. Perform a manual test on the server. Running another scanner to compare (Option A) can help to confirm the results but is not necessarily the best way to ensure the vulnerability is a true positive. Checking the results on the scanner (Option C) and looking for the vulnerability online (Option D) are not reliable methods for confirming the vulnerability. Performing a manual test on the server (Option B) is the best way to ensure the vulnerability is a true positive as it allows the tester to directly interact with the server and confirm the vulnerability exists.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago