During a vulnerability assessment, an analyst manually confirms that a reported weakness actually exists on the target host. Which result classification best describes this verified finding?
A true positive is a detection that correctly identifies a real vulnerability. Once the analyst validates that the weakness is present, the result is confirmed as a true positive. In contrast, a false positive is a reported vulnerability that proves nonexistent after validation, a false negative is a real vulnerability the scanner missed, and a true negative correctly indicates the absence of a vulnerability.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between a false positive and an accurate detection?
Open an interactive chat with Bash
How are vulnerabilities actively tested to confirm they are real risks?
Open an interactive chat with Bash
Why is it important to differentiate false positives from real vulnerabilities?