39.1k views
3 votes
An organization wants to remediate vulnerabilities associated with its web servers. An initial vulnerability scan has been performed, and analysts are reviewing the results. Before starting any remediation, the analysts want to remove false positives to avoid spending time on issues that are not actual vulnerabilities. Which of the following would be an indicator of a likely false positive?

A. Reports show the scanner compliance plug-in is out-of-date.
B. Any items labeled 'low' are considered informational only.
C. The scan result version is different from the automated asset inventory.
D. 'HTTPS' entries indicate the web page is encrypted securely.

1 Answer

0 votes

Answer: (B) Any items labeled 'low' are considered informational only.

Step-by-step explanation:

Any items labeled 'low' are considered informational only. These can be avoided as the analyst do not want to spend time on issue that are not actual vulnerable.

User Lpacheco
by
4.8k points