A vulnerability scan returns a finding with plugin metadata stating severity: informational, category: policy check, and no CVE. The scanner also notes it does not confirm remote code execution. As an analyst, what should you do with this finding?
Select an answer to reveal the explanation.
Short Explanation
Think of scanner metadata like a nutrition label: it tells you what the check measured, not automatically what’s dangerous. If the plugin says informational and policy check, you don’t jump to exploit panic; you ask whether it violates your baseline. That’s how you separate real risk from noise.
Full Explanation
Scanner output is more than a list of findings; plugin metadata tells you what the check was designed to determine. An informational severity with a policy-check category and no CVE or exploit proof usually means the scanner observed a condition that may violate a baseline, not a confirmed exploitable vulnerability. Actionable data comes from correlating metadata with asset exposure, required controls, and proof. A finding can still matter if it shows disabled logging or weak authentication settings, but priority depends on policy relevance and exploitability. Treating it as a critical exploit is wrong because the metadata lacks critical severity and exploit evidence. Escalating it as ransomware is wrong because vulnerability metadata alone does not provide behavioral indicators, indicators of compromise, or attack-chain context. Suppressing it permanently as a false positive is wrong because informational and policy findings can be accurate control gaps; suppression should be based on verified risk acceptance or duplicate evidence. Exam caveat: on the CS0-004, do not assume every scanner result is a vulnerability to patch; classify findings by what the plugin actually checked. Operational check: review the plugin description, category, severity, and references, then map the observed setting to the hardening standard before deciding whether to remediate, accept, or suppress.