During a vulnerability assessment, an analyst manually confirms that a reported weakness actually exists on the target host. Which result classification best describes this verified finding?
A true positive is a detection that correctly identifies a real vulnerability. Once the analyst validates that the weakness is present, the result is confirmed as a true positive. In contrast, a false positive is a reported vulnerability that proves nonexistent after validation, a false negative is a real vulnerability the scanner missed, and a true negative correctly indicates the absence of a vulnerability.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a true positive in vulnerability assessment?
Open an interactive chat with Bash
How is a true positive different from a false positive?
Open an interactive chat with Bash
What are the consequences of a false negative in a vulnerability assessment?