exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 39 discussion

Actual exam question from CompTIA's SY0-501
Question #: 39
Topic #: 1
[All SY0-501 Questions]

An organization is using a tool to perform a source code review. Which of the following describes the case in which the tool incorrectly identifies the vulnerability?

  • A. False negative
  • B. True negative
  • C. False positive
  • D. True positive
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SirFrates24
Highly Voted 4 years, 11 months ago
A false positive is a false alarm. A false negative state is the most serious and dangerous state. This is when the IDS identifies an activity as acceptable when the activity is actually an attack. That is, a false negative is when the IDS fails to catch an attack.
upvoted 8 times
...
Hanzero
Most Recent 4 years, 7 months ago
False positive is the answer. Incorrectly identifies a vulnerability meaning vulnerability doesn't exist but it still identifies it which might waste a lot of resources in verifying it.
upvoted 2 times
...
Tauhid
4 years, 8 months ago
Answer: C (False Positive) A false positive incorrectly raises an alert indicating an attack when an attack is not active. False positives increase the workload of administrators. A false negative is when an attack is active, but not reported. Source: Get Certified Get Ahead.
upvoted 2 times
...
Arist
4 years, 9 months ago
Answer False Positive. From NIST.gov on IDPS states: "Incorrectly identifying benign activity as malicious is known as a false positive; the opposite case, failing to identify malicious activity, is a false negative."
upvoted 1 times
...
mlonz
4 years, 9 months ago
I am trying hard but I am not remembering this false positive and false negative and i am thinking to become a pen tester, God Help me :D
upvoted 1 times
Duranio
4 years, 9 months ago
It's pretty easy: it's works like in medical tests. If the test IDENTIFIES something, the result is POSITIVE; if this "thing" that was identified is correct (correct identification of a problem) then it's a TRUE POSITIVE; if the "thing" that was identified is incorrect (incorrect identification of a problem) then it's a FALSE POSITIVE. On the opposite side if the test does NOT identify any desease, the result is NEGATIVE; if there was really no desease to find, then it is a TRUE NEGATIVE; if there was something to find (and the test didn't find it) then it is a FALSE NEGATIVE. In this case it identified something, so the result is POSITIVE; however as this identification was incorrect ("incorrectly identified") it is a FALSE POSITIVE.
upvoted 8 times
...
...
Blaze42
4 years, 9 months ago
False Negative is correct. It specifies a VULNERABILITY being identified incorrectly, therefore the threat exists but is not identified. By the way, I think that a lot of the answers are marked wrong on purpose by the website admins. This might allow them to not get shut down for test compromise. Not sure though.
upvoted 1 times
...
Crimson
4 years, 9 months ago
Really confused about this one because a vulnerability is a negative thing. So INCORRECTLY identifying a NEGATIVE thing should a FALSE NEGATIVE
upvoted 1 times
...
MagicianRecon
4 years, 10 months ago
Incorrectly identifies the vulnerability - should be false negative
upvoted 2 times
...
AWS_NEWBIE_2020
4 years, 10 months ago
It should be 'false positive' because "incorrectly identify the vulnerability" means there are actually NO vulnerability, which stands for a ''positive' thing.
upvoted 1 times
...
SirFrates24
4 years, 11 months ago
false positive would be the answer since a source code review is the examination of an application source code to find errors overlooked in the intial development phase. A tester launches a code analyzer thats scans line by line of an application. Once the analyzer finds vulnerabilities,, the pentester manually checks them to eliminate false positives
upvoted 1 times
...
colamix
4 years, 11 months ago
My notion is "Positive = identified and negative = rejected"
upvoted 1 times
...
Ender89
4 years, 12 months ago
This should be false negative. It says that it "incorrectly identified THE vulnerability", meaning that there is a vulnerability that wasn't identified. from www.whitehatsec.com: "False Positives occur when a scanner, Web Application Firewall (WAF), or Intrusion Prevention System (IPS) flags a security vulnerability that you do not have. A false negative is the opposite of a false positive, telling you that you don't have a vulnerability when in fact you do". We have a vulnerability that wasn't detected, therefore it's a false negative.
upvoted 2 times
...
ClintBeavers
5 years ago
incorrectly identifies a vulnerability implies that a vulnerability exists, and if it exists and incorrectly identified, then it is a false negative. a false positive is when there is no vulnerability but the system identifies ones anyways.
upvoted 1 times
Ender89
4 years, 12 months ago
"incorrectly identifies a vulnerability" would mean that it identified a vulnerability that doesn't exist and is a false positive. "Incorrectly identifies the vulnerability" is a false negative since it didn't identify the vulnerability that exists.
upvoted 4 times
...
...
ClintBeavers
5 years ago
should be False negative. the question ask "when incorrectly identifies a vulnerability" a vulnerability is a risk, and incorrect is false, therefore, false negative.
upvoted 3 times
...
zaws
5 years, 3 months ago
False Positive: a test result which incorrectly indicates that a particular condition or attribute is present.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago