Mark a vulnerable item (VI) or remediation task (VUL) as a false positive if the warning given by the scanner is not actually an issue. For example, if a configuration item has been decommissioned but the scanner is still raising an issue related to it, mark it as a false positive.

Before you begin

Role required: remediation owner

You can request false positives from the Vulnerability Response Workspaces. See Request a false positive for a vulnerable item or remediate task.

You can also request false positives in the classic environment:

Procedure

  1. Navigate to Vulnerability Response > Vulnerable Items (or Remediation Tasks) > All.
  2. Open the VI or VUL you want to mark as a false positive and click Mark as False Positive.
    The VI or VUL must be in an Open state.
  3. On the False Positive form, enter details in Additional information and click Request Approval.
    The request is sent for approval and the State of the VI or VUL changes to In Review.