A vulnerability report sent to remediation teams includes several false positives and duplicate findings. The analyst wants to preserve trust in the report while acknowledging scanner limitations. Which action best supports accurate reporting?
Select an answer to reveal the explanation.
Short Explanation
Think of a vulnerability report like a scoreboard: if you quietly erase bad calls, nobody trusts the next game. Flag the false positives and duplicates, then ask for scanner tuning so the record stays honest.
Full Explanation
Vulnerability reporting credibility depends on transparency and traceability. When a scanner produces duplicates or false positives, the analyst should keep the report honest by identifying them as known scanner artifacts and routing feedback to the scanner or platform owner for tuning, deduplication, or authenticated-scan improvements. This preserves the audit trail, prevents hidden data loss, and gives remediation owners a clear explanation instead of a silent deletion. Removing questionable findings without documentation hides evidence and can make future reports appear inconsistent, especially when the same finding reappears later. Treating every scanner result as confirmed risk overstates exposure and discourages useful validation, which is essential when CVSS scores, exploitability, and asset context differ. Sending a separate apology after the report fragments the record and leaves the original report still containing misleading entries unless it is formally revised. Exam caveat: vulnerability reports should distinguish raw scanner output from validated risk. Operational check: maintain a findings-disposition log that tags duplicates, false positives, accepted risks, and remediation status, then reconcile it before each recurring report.