A scanner report flags a Windows host because local password policy allows 4-character passwords and no account lockout. The finding cites no CVE, affected package version, or exploit code. How should an analyst classify this finding for remediation?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: if the problem is a door left unlocked, you don't call the locksmith for a broken lock; you fix the policy. A weak password and lockout setting is a configuration risk, not a CVE-backed software flaw. You should harden the group policy and then re-scan to prove the setting changed.
Full Explanation
Vulnerability assessment tools often return two kinds of findings. A software vulnerability is tied to a defect in code, a library, or a service and usually includes a CVE, affected package version, or exploit reference. When the report instead says password length is too short and lockout is disabled, the finding is describing unsafe settings in the operating system. That makes it a configuration risk, so remediation means hardening authentication policy through group policy or a baseline, then rescanning to confirm the settings match the standard. A software vulnerability classification is wrong because the scanner did not identify a patchable defect or vulnerable component version. A compliance exception classification is also wrong because an exception is a formal risk acceptance, not a technical category, and the absence of an exploit does not erase the weak setting. A false-positive classification is wrong because the scanner accurately detected a real policy deviation; false positives require evidence that the reported condition does not exist. Exam caveat: CS0-004 expects you to read scanner output and classify findings by root cause, not by the tool severity label. Operational check: verify the local password policy and lockout threshold against the approved hardening baseline, then validate the corrected setting with a targeted scan.