nerdexam
CompTIA

SY0-501 · Question #437

A security analyst conducts a manual scan on a known hardened host that identifies many non- compliant items. Which of the following BEST describe why this has occurred? (Select TWO)

The correct answer is B. Non-applicable plug ins were selected in the scan policy C. The incorrect audit file was used. When a vulnerability scan on a hardened host unexpectedly reports many non-compliant items, the most likely causes are misconfigured scan policies or incorrect audit/benchmark files being applied during the assessment.

Submitted by parkjh· Mar 4, 2026Security operations

Question

A security analyst conducts a manual scan on a known hardened host that identifies many non- compliant items. Which of the following BEST describe why this has occurred? (Select TWO)

Options

  • APrivileged-user certificated were used to scan the host
  • BNon-applicable plug ins were selected in the scan policy
  • CThe incorrect audit file was used
  • DThe output of the report contains false positives
  • EThe target host has been compromised

How the community answered

(28 responses)
  • A
    14% (4)
  • B
    75% (21)
  • D
    4% (1)
  • E
    7% (2)

Why each option

When a vulnerability scan on a hardened host unexpectedly reports many non-compliant items, the most likely causes are misconfigured scan policies or incorrect audit/benchmark files being applied during the assessment.

APrivileged-user certificated were used to scan the host

Using privileged credentials actually improves scan accuracy by allowing deeper access to the host, and would more likely reduce false positives rather than generate excessive non-compliant findings.

BNon-applicable plug ins were selected in the scan policyCorrect

Selecting non-applicable plugins in the scan policy causes the scanner to check for vulnerabilities or configurations that do not apply to the target OS or application, generating false non-compliance findings that misrepresent the host's actual security posture.

CThe incorrect audit file was usedCorrect

Audit files define the specific compliance benchmarks (e.g., CIS, STIG) checked against the host; using an incorrect audit file - such as applying a Windows benchmark to a Linux host - will produce numerous spurious non-compliant results because the checks do not match the target system's configuration.

DThe output of the report contains false positives

While false positives can occur in scan results, this choice describes a symptom rather than a root cause explaining why a hardened host shows many non-compliant items.

EThe target host has been compromised

A compromised host is possible but is not the best explanation for many non-compliant findings on a known hardened host, as the scenario points to a scanning configuration issue rather than an active breach.

Concept tested: Vulnerability scan policy and audit file misconfiguration

Source: https://docs.tenable.com/nessus/Content/ScanAndPolicyTemplates.htm

Topics

#vulnerability scanning#compliance scanning#audit files#false positives

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice