ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 240 - SY0-601 discussion

Report
Export

An organization recently released a software assurance policy that requires developers to run code scans each night on the repository. After the first night, the security team alerted the developers that more than 2,000 findings were reported and need to be addressed. Which of the following is the MOST likely cause for the high number of findings?

A.
The vulnerability scanner was not properly configured and generated a high number of false positives
Answers
A.
The vulnerability scanner was not properly configured and generated a high number of false positives
B.
Third-party libraries have been loaded into the repository and should be removed from the codebase.
Answers
B.
Third-party libraries have been loaded into the repository and should be removed from the codebase.
C.
The vulnerability scanner found several memory leaks during runtime, causing duplicate reports for the same issue.
Answers
C.
The vulnerability scanner found several memory leaks during runtime, causing duplicate reports for the same issue.
D.
The vulnerability scanner was not loaded with the correct benchmarks and needs to be updated.
Answers
D.
The vulnerability scanner was not loaded with the correct benchmarks and needs to be updated.
Suggested answer: A

Explanation:

The most likely cause for the high number of findings is that the vulnerability scanner was not properly configured and generated a high number of false positives. False positive results occur when a vulnerability scanner incorrectly identifies a non-vulnerable system or application as being vulnerable. This can happen due to incorrect configuration, over-sensitive rule sets, or outdated scan databases.

https://www.professormesser.com/security-plus/sy0-601/sy0-601-video/sy0-601-comptia-security- plus-course/

asked 02/10/2024
Szymon Strzep
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first