An unauthenticated scan flags missing SMB signing on a Windows file server using only banner and version heuristics. A later authenticated local check confirms SMB signing is enforced. How should the analyst classify the original scan result?
Select an answer to reveal the explanation.
Short Explanation
Think of an unauthenticated scan as peeking through a door crack: it can guess, but it cannot prove what is inside. If a local authenticated check says SMB signing is enforced, your banner-based finding is likely a false positive. You should chase the missing proof, not panic about a phantom patch.
Full Explanation
An unauthenticated vulnerability assessment often relies on remote banners, protocol responses, and version strings to infer configuration. When a security control depends on local policy or runtime enforcement, that inference is weaker because the scanner cannot inspect registry values, effective policies, or process behavior. The correct interpretation is that the finding is likely a false positive created by an authenticated-validation gap, and the analyst should correlate it with local evidence before remediation. A confirmed finding requiring immediate patching is wrong because patching addresses missing code updates, not a configuration control already demonstrated as enforced. A confirmed finding requiring credential exposure is also wrong because exposing credentials is not a remediation outcome and does not resolve a scanner limitation. A true positive supported only by banner heuristics is wrong because heuristic evidence may be useful for prioritization, but it is insufficient when an authenticated local check contradicts it. Exam caveat: CS0-004 often tests whether you understand scanner confidence and validation method, not just the presence of a CVE-like alert. Operational check: rerun the scan with authenticated credentials and compare the remote heuristic result against the local SMB signing policy status.