19 Analyzing Scan Output Practice Questions & Answers
Every Analyzing Scan Output practice question from the CompTIA CySA+ Practice Test, with the correct answer and a short explanation.
Start practice test →1. An uncredentialed scan of a Linux web server reports eleven critical findings. A credentialed scan of the same host two hours later reports three, and the eight that disappeared were all detected from service banners. Nothing was patched in between. What does this comparison most reliably establish?
- A.The credentialed run authenticated and therefore suppressed findings it could only see over the network, so the uncredentialed count of eleven is the safer number to report.
- B.The two-hour gap let an automatic update service remediate eight issues, so the difference reflects patching applied rather than any difference between the two scan methods.
- C.The credentialed run could read the installed package versions, so the eight banner-only detections must be treated as unconfirmed until they are checked on the host itself.✓ Answer
- D.The credentialed run holds a login and so reports only configuration findings, which means the eight missing items are network-layer flaws that only an uncredentialed run sees.
A credentialed check logs in and reads the actual installed package and patch state, so it resolves what a banner can only suggest. Banner or version inference is the leading source of false positives, so the eight detections that only the uncredentialed run produced are unvalidated claims, not remediated items.
Source: CompTIA CySA+ CS0-004 Objective 2.2 (analyze output from vulnerability assessment tools), with 2.1 credentialed vs non-credentialed scanningReport a problem with this question
2. A scan report lists 'web server 2.4.29 - multiple critical vulnerabilities' on port 443 of a host, and the evidence field contains only an HTTP Server response header. The host is a reverse proxy that terminates TLS and forwards requests to application servers. Before a remediation ticket is opened, what is the correct action?
- A.Open the ticket against the application servers behind the proxy, since the Server header the scanner read is the one they emit across the forwarded connection.
- B.Close the finding as a false positive, because a Server response header can be set to any value at all and therefore never constitutes evidence of a real software version.
- C.Accept the reported version and schedule the upgrade, because the banner is returned by the listening service itself and matches the scanner's plugin signature for that release.
- D.Confirm on the proxy itself which package actually serves port 443, and at what version and patch level, before anyone is asked to act; then record that evidence on the finding itself.✓ Answer
A finding inferred from a response header is a hypothesis about the software, and on a proxy the header may describe the proxy, a backend, or nothing at all. Validation means determining on the host what is actually listening and at what patch level, and attaching that evidence, before anyone is asked to act on the finding.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - validate findings and identify false positives before remediationReport a problem with this question
3. A quarterly scan flags 'SSL certificate cannot be trusted' on forty internal management interfaces. Every certificate was issued by the organization's own internal certificate authority, whose root is distributed to managed endpoints but is not present in the scanner's trust store. How should these findings be read?
- A.As an artifact of the scanner's own trust configuration: import the internal root into the scanner and rescan, so that genuine expiry or key-strength problems still surface.✓ Answer
- B.As forty genuine certificate failures: replace every certificate with one from a commercial public authority so that any scanner anywhere validates the chain with no extra setup.
- C.As proof that the internal authority has been compromised, since a correctly operated authority issues chains that every scanner validates from its default trust store.
- D.As findings that can be suppressed permanently by rule on this host group, because a certificate from an internal authority never carries risk that a scanner could detect.
The condition reported is 'the scanner cannot build a trusted chain', which here follows from the scanner's trust store rather than from a defect in the certificates. Fixing the scanner's trust configuration removes the noise while keeping the plugin able to report the real certificate problems, which blanket suppression would also hide.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - false positives arising from tool configuration versus genuine weaknessReport a problem with this question
4. A vulnerability manager reviewing scan quality asks why a false negative is treated as the more serious defect than a false positive. Which statement is accurate?
- A.A false negative is a finding the scanner downgraded in severity, so it is recorded but ranked wrongly, whereas a false positive is never written into the report at all.
- B.A false negative leaves a real exposure unrecorded, so nobody triages or tracks it, while a false positive is visible and gets removed once someone validates the finding.✓ Answer
- C.A false negative spends analyst hours on a condition that does not exist, whereas a false positive is corrected automatically the next time the plugin feed is refreshed.
- D.A false negative appears only in uncredentialed scans and a false positive only in credentialed ones, so the credentialed report is the one whose contents can be trusted.
A false positive is self-correcting because it enters the queue and validation removes it; the cost is wasted effort. A false negative never enters the queue at all, so the exposure is carried silently and the programme reports coverage it does not have, which is why scan configuration aims to minimise misses first.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - false positives and false negatives in assessment outputReport a problem with this question
5. A scan of a 50-host database subnet returns no critical findings. The report summary shows that credential authentication succeeded on 9 hosts and failed on 41, and that those 41 were assessed from the network only. What should the analyst conclude?
- A.The subnet is confirmed healthy for this cycle, because a host that refuses the scanner's credentials has hardened authentication and is unlikely to be missing patches.
- B.The 41 authentication failures are themselves this cycle's critical finding and should be raised as one access-control defect, with the coverage question closed by that ticket.
- C.The clean result is not evidence of a clean subnet: 41 hosts were assessed with no patch visibility and must be rescanned once the credential problem has been fixed.✓ Answer
- D.The result can be published with the credential failures noted in an appendix, since network-based checks reach the same plugins that an authenticated check would have run.
Authentication failure on 41 of 50 hosts means most of the subnet was checked only for what a network probe can see, so missing patches and insecure local configuration were never assessed. The absence of findings measures scan coverage, not host health, and the correct response is to restore credentialed access and rescan.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - causes of false negatives, including failed credentials and incomplete coverageReport a problem with this question
6. An analyst discovers that the scanner's vulnerability plugin feed was last updated seven months ago, and that several quarterly reports were issued and signed off during that period. What does this do to those reports?
- A.It inflates them: an ageing feed keeps firing checks that were retired, so those reports overstate exposure and the clean step is to close the aged findings in bulk.
- B.It leaves them valid for the assets they covered, because plugin content governs only the wording of the remediation advice rather than which conditions get detected.
- C.It affects only the credentialed checks, since network-based plugins derive their results from live service responses and therefore stay current whatever the feed age.
- D.It undermines them through omission: nothing disclosed since that update could be detected, so the reports understate exposure and the scans have to be rerun.✓ Answer
A scanner can only report conditions its detection content knows about, so an unmaintained feed produces systematic false negatives for everything disclosed since the last update. The reports therefore understate exposure, and their credibility is restored only by updating the detection content and scanning again.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - plugin/feed currency as a source of false negatives affecting report credibilityReport a problem with this question
7. A credentialed scan reports a critical remote-code-execution flaw in an XML parsing extension on an application server. Verification shows the package is installed but the extension is not loaded by the running service, and no configuration file references it. What is the correct reading?
- A.The finding is a false positive and should be closed, because a scanner that reports an unloaded component has misidentified the software actually present on the host.
- B.The finding should be escalated for emergency patching, because an installed package can be loaded at any moment by a local user and so it is actively exploitable today.
- C.The finding belongs with the network team as an exposure question, because whether a parsing library is reachable is decided by firewall rules rather than by the host itself.
- D.The finding is accurate about the installed package but not reachable in the current configuration: record that evidence, remove or update the package, and then rescan.✓ Answer
Validation separates two different questions: is the vulnerable component present, and is it in a path an attacker can reach. Here the first is confirmed and the second is not, so the honest record is a real finding with documented unreachability, still remediated by removing or updating the package rather than closed as imaginary.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - components present but not enabled or not reachable in scan outputReport a problem with this question
8. A scanner reports a critical injection flaw in an internet-facing web application. The vendor patch cannot be applied for six weeks, and a web application firewall rule now blocks the exploit request pattern. The application owner asks that the finding be recorded as a false positive. How should it be recorded?
- A.As a closed finding, since the firewall rule is the remediation the business chose and a finding is closed by whatever control removes exploitability, not only by a patch.
- B.As a false positive, because the exploit no longer succeeds against the deployed system and a finding that cannot be reproduced end to end fails validation by definition.
- C.As a confirmed finding whose exposure a compensating control reduces: kept open, with the rule documented and a remediation date, and verified by rescan after patching.✓ Answer
- D.As a new configuration finding against the firewall that replaces the application finding, because the defect now tracked is the rule's coverage rather than the unpatched code.
A false positive means the reported condition is not present. Here the vulnerable code is present and confirmed; a compensating control only blocks a known exploitation path and can be bypassed or misconfigured. Recording it as a false positive would erase the defect from the record and remove the driver for the patch.
Source: CompTIA CySA+ CS0-004 Objective 2.2 with 2.3 compensating controls - reduced exposure is not an invalid findingReport a problem with this question
9. A scan flags a hardening setting missing on one newly built virtual server. The build team confirms that every server in that environment is deployed from a single virtual machine template. What does the single finding actually indicate?
- A.A defect in the template, which is therefore latent on every host built from it: correct the template first, then scan the fleet to enumerate the instances already deployed.✓ Answer
- B.A drift event on that host, meaning the setting was changed after deployment, so the fix is to restore the host from the template and watch for further drift.
- C.A scoping error in the scan, since a host derived from a template inherits its configuration and cannot hold a finding that the template itself does not present.
- D.A defect on that one host, correctable in place; the other servers are covered because the template's own scan history contains no equivalent finding against it.
When hosts share a build source, a configuration finding on one instance is usually a property of that source, so the real population is every system built from it plus every future build. Reading it as a single-host defect leaves the same condition unrecorded elsewhere and reintroduced at the next deployment.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - a finding on one host as evidence about a shared image or templateReport a problem with this question
10. A scan of a running container reports a vulnerable system library. An engineer updates the package inside the running container and the rescan comes back clean. Why is this not an adequate remediation?
- A.Because containers are recreated from their image at the next deployment, so the vulnerable library returns unless the fix is made in the image build and the image rebuilt.✓ Answer
- B.Because a package updated inside a container is reported against the host kernel instead, so the clean rescan reflects a change of scope and no change to the library.
- C.Because library findings inside containers can only be validated from outside the runtime, so a rescan performed against the running container cannot confirm any remediation.
- D.Because the container's package manager writes to a layer the scanner cannot read, so the clean result means the check was skipped rather than that the library passed it.
Container instances are disposable and are rebuilt from an image, so a change made in a running instance lives only until that instance is replaced. The finding is really about the image, and the clean rescan proves only that this instance changed; durable closure requires the base image or Dockerfile to be fixed and the image redeployed.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - container image and base image findings in assessment outputReport a problem with this question
11. Findings for the same vulnerable serialization library appear on 63 hosts across four business applications. Management asks for 63 separate remediation tickets. What is the more accurate way to represent this work?
- A.1 library defect with 63 affected instances, traced through the software inventory to the builds that bundle it, with closure still verified per host by rescan.✓ Answer
- B.4 application findings, one per business application, because the library reaches a host only through the application that bundles it and each owner patches separately.
- C.63 independent host findings, because each host has its own patch window and owner, and a single ticket would hide which hosts still remain unremediated at the end.
- D.1 host finding on whichever host carries the highest asset criticality, with the other 62 recorded as duplicates of it and closed when that host is remediated.
Consolidation means grouping detections that describe one underlying condition while keeping the affected-instance count intact. Treating a bundled library as one defect with 63 instances lets the software inventory answer where else it is present, and per-host rescan still proves each instance closed.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - consolidating findings and tracing them to a shared component via software inventoryReport a problem with this question
12. An infrastructure-as-code scan flags a template that opens a management port to 0.0.0.0/0. A check of the deployed environment shows the live resource restricts that port to two administrative addresses. What does the finding indicate?
- A.This is a real defect in the template, which will reopen the port the next time the environment is built from it, even though today's deployed setting is restricted.✓ Answer
- B.This is a false positive, because the scanner read a declaration rather than a live configuration, and a valid finding must describe the state of a deployed resource.
- C.This is a drift finding against the live resource, since the template is the authoritative record and any deployed setting that differs from it is what must be corrected.
- D.This is a duplicate of the network-layer finding, because the deployed restriction already satisfies the control and template text carries no exposure of its own to track.
A template is the definition future environments inherit, so a permissive rule in it is a genuine finding even when the current deployment was tightened by hand. The manual restriction is itself unmanaged state that the next build overwrites, so the defect is fixed in the template and the deployed resource is rechecked afterwards.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - infrastructure-as-code misconfiguration findingsReport a problem with this question
13. A monthly report counts 4,812 open findings. Review shows that the same CVE on one host is counted once per open port, and counted again from a second scanner's plugin for the same condition. What must be done before the number is reported?
- A.Report the raw total with a footnote about the overlap, because any reduction applied by hand to a scanner's output weakens the audit trail the report exists to provide.
- B.Keep only the scanner with the larger finding count and retire the other entirely, so that the total comes from one consistent source and stays comparable month to month.
- C.Consolidate across tools and deduplicate to unique vulnerability-per-asset pairs, so the total counts distinct conditions rather than repeated detections of the same one.✓ Answer
- D.Report each scanner's total separately without merging them, since two tools measure different conditions and a combined figure cannot be reconciled to either report.
The published count should answer how many distinct conditions exist, so multi-port and multi-tool detections of one condition on one asset are one finding. Without consolidation and deduplication the total inflates with tool coverage, and trend lines then track scanning changes instead of real remediation progress.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - consolidating and deduplicating findings across multiple assessment toolsReport a problem with this question
14. A dynamic application scan reports SQL injection on a search parameter. The evidence is a database error message returned in the HTTP response after the scanner appended a single quote to the input. How should the analyst establish whether this is real?
- A.Take the error message as sufficient proof, because a verbose database error returned to a client shows that user input reached the database engine unparameterized.
- B.Reproduce the request in a test environment with a harmless payload that changes the query's result set, and inspect the code path or query log for unparameterized input.✓ Answer
- C.Close the finding unless the scanner also returned extracted table names, since an injection report with no retrieved data is a detection artifact rather than a finding.
- D.Ask the developer whether the parameter is validated and record the answer on the finding, because code ownership settles an injection question faster than testing does.
An error message proves only that malformed input changed the response; it can also come from input validation or from framework error handling with the query still parameterized. Confirmation requires showing that injected syntax alters query behaviour, or reading the code or query log, which is why validation precedes any remediation ticket.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - validating web application findings such as SQL injectionReport a problem with this question
15. An authenticated dynamic scan reports stored cross-site scripting in an internal ticketing application. The affected form is reachable only by logged-in staff, and the application is not exposed to the internet. What does the finding establish?
- A.Nothing until the scan is repeated with no credentials, because a flaw an anonymous request cannot reach is an access-control observation rather than an injection finding.
- B.That the scanner injected its own payload and read it back again, which is self-detection; stored cross-site scripting counts only if a separate second session renders it.
- C.That the finding belongs to the identity team, since an application whose flaw needs a valid session is defended by session controls rather than by output encoding.
- D.That the injection flaw is genuine and confirmed; the login requirement and the lack of internet exposure describe who is able to reach it, not whether the input handling is defective.✓ Answer
Reachability and validity are separate judgements. The scan authenticated as a legitimate user and the payload was stored and rendered, so the input-handling defect is confirmed; requiring a session and having no internet path narrows who can exploit it and belongs in the prioritization record, not in a false-positive decision.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - reading web application findings for exploitability in contextReport a problem with this question
16. A credentialed web scan returns a finding whose evidence is an unlinked file in the site's upload directory that accepts a command parameter and returns command output, with a modification date three weeks old. How should this be handled?
- A.As a high-severity application finding: delete the file, record the remediation, and close the item at the next rescan once the URL no longer returns command output.
- B.As a scanner artifact: some plugins write interactive test files during an assessment, so the item should be suppressed and the upload directory excluded from scope.
- C.As a sign of a compromise that has already happened: preserve the file and host evidence, invoke incident response, and scope the event before anything is altered.✓ Answer
- D.As a configuration finding against the web server: disable script execution in the upload directory, which removes exploitability without needing to touch the file itself.
Some scan output describes a weakness, and some describes an event. A file placed in a writable directory weeks ago that executes attacker-supplied commands is not a missing patch or setting; it is working attacker tooling, so the correct path is evidence preservation and incident response rather than deleting it and closing a ticket.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - distinguishing a vulnerability finding from evidence of an incidentReport a problem with this question
17. A scan reports that a departmental server runs an operating system release the vendor stopped supporting last year, and lists no available patch for the eight critical findings on that host. How should the analyst read this set of findings?
- A.As eight patch items awaiting a vendor release, tracked with a deferred due date and rescanned monthly until the updates the findings reference become available.
- B.As an accurate and permanent condition: no patch will ever exist, so remediation means upgrading or replacing the platform, with isolation as the interim control.✓ Answer
- C.As findings to suppress under an exception, since a scanner cannot assess a release whose plugin content the vendor no longer maintains and the results are unreliable.
- D.As a licensing and inventory record rather than a security condition, because an unsupported release adds no exposure until a specific exploit has been published.
End-of-life findings differ from missing-patch findings in that the remediation path does not exist and the count can only grow as new issues are disclosed. Reading them as deferred patch work creates a due date that can never be met, so the finding must be recorded as a platform replacement with an interim containment control.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - end-of-life/unsupported software findings versus missing patchesReport a problem with this question
18. A scan flags 'server supports deprecated TLS protocol versions and weak cipher suites' on an application host. The web server package itself is fully patched. What does this finding say, and where does remediation belong?
- A.It is a missing-patch finding the scanner attributed to the wrong package, so the step is to open a vendor case and wait for a release that removes those cipher suites.
- B.It is a configuration finding: the protocol and cipher list is set in the server's own configuration, so remediation is a hardening change confirmed by a verification rescan.✓ Answer
- C.It is a certificate finding, so reissuing the certificate with a stronger key and a current signature algorithm will withdraw the deprecated protocol versions from service.
- D.It is a false positive whenever the package is current, because a fully patched server offers only the protocol versions and cipher suites its vendor considers acceptable.
Scan output separates missing patches from misconfiguration, and this finding is the second kind: the software is current but is configured to negotiate protocols and ciphers that policy no longer allows. Remediation is an owner-side configuration change and hardening baseline update, proved by rescanning the service afterwards.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - distinguishing misconfiguration findings from missing-patch findingsReport a problem with this question
19. Consolidated results list fourteen distinct findings across six in-house applications. They differ in location and parameter, but all fourteen map to the same weakness class, improper neutralization of special elements used in an SQL command. What does that pattern indicate?
- A.That the fourteen are duplicates of one condition and should be merged into a single item, since findings sharing a weakness class describe the same underlying defect.
- B.That the same coding weakness recurs across teams, so beyond the fourteen fixes the durable remediation is a development practice change verified by pipeline checks.✓ Answer
- C.That the weakness class was assigned incorrectly, because that class describes defects in the database platform itself rather than input handling in application code.
- D.That the applications share a vulnerable database driver, so one library update at the platform layer will clear all fourteen findings with no application change at all.
A weakness class names the kind of coding error, while each finding is a separate instance of it in its own code path, so the fourteen are not duplicates and cannot be closed by one library fix. Clustering on one class across six applications points at the shared practice that produces the error.
Source: CompTIA CySA+ CS0-004 Objective 2.2 - weakness class (CWE) versus individual vulnerability instances in consolidated outputReport a problem with this question
Practice questions based on the CompTIA CySA+ exam objectives. This site is not affiliated with or endorsed by CompTIA, and these are not real exam questions. CompTIA refreshes this exam periodically, runs two versions side by side during a transition, and sets the exam length, passing standard and eligibility terms — confirm the current objectives and the live exam code with CompTIA before you register. The real exam also includes performance-based items that a multiple-choice bank cannot reproduce, so pair this with hands-on practice. Official CySA+ exam objectives →