A patch report shows a missing security update on an internal server. The vulnerability scanner also confirms the affected service is reachable from the analyst's network. Which conclusion is best supported by the output?
Select an answer to reveal the explanation.
Short Explanation
Think of a missing patch like a missing brick in a fence you can still reach. If the scanner says the service is reachable, you can't call it just a paperwork gap. You treat the missing update as real exposure until the service is patched or isolated.
Full Explanation
A vulnerability scanner combines compliance data with reachability checks to turn a missing update into a risk assessment. A patch report alone says the required code is absent; a service reachable from the analyst network says the vulnerable code can be contacted. Together, those facts support treating the host as exposed to the vulnerability until remediation or isolation reduces exposure. A finding is not a false positive merely because no exploit was attempted during the assessment; vulnerability assessment generally identifies weakness without active exploitation. A missing update also does not prove a compensating control exists; controls such as segmentation, WAF rules, or disabled services must be verified separately. A host is not automatically safe because an external scanner has not yet confirmed it; internal reachability can be enough for exposure, and external scanning may be blocked or irrelevant for lateral movement. Exam caveat: distinguish patch status, service availability, and exploitability when interpreting scanner output. Operational check: re-scan the affected port, verify the service banner or version, and document whether network controls or compensating controls reduce exposure.