Request a false positive for a vulnerable item or remediate task

  • Rversion finale: Australia
  • Mis à jour 13 mars 2026
  • 1 minute de lecture
  • Indicate a false positive request for a finding or a remediation task in the Security Exposure Management Workspace. A false positive is a condition where a scanner incorrectly reports that a finding exists in the system due to situations such as an incorrect classification, improper logic, or an algorithm in the scanner.

    Avant de commencer

    Role required:
    • sn_vul.remediation_owner for host vulnerable items (VITs)
    • sn_vul.app_security_champion for application vulnerable items (AVITs)
    • sn_vul_container.remediation_owner for container vulnerable items (CVITs)
    • sn_vulc.remediation_owner for configuration test results (CTRs)

    Pourquoi et quand exécuter cette tâche

    Procédure

    1. Navigate to Workspaces > Security Exposure Management Workspace.
    2. Select List icon .
    3. Select the remediation task or vulnerable item.
    4. Select Mark as False Positive.
    5. Enter information about the request.
    6. Select Request Approval.
    7. Provide additional information about your request to the approver and select Submit.
      Remarque :
      The Take Questionnaire modal appears only when the Enable questionnaire to mark false positive check box is selected in the Exception Management Configuration form. .

    Résultats

    The state of the vulnerable item or remediation task transitions to In Review.

    Your request is submitted for approval and the approver receives an email notification about your request.

    You will receive an email notification upon approval or rejection of your request.

    Que faire ensuite

    In the Security Exposure Management Workspace, on the List page, navigate to Exception Requests > My requests and open the corresponding state change approval record (VCA#) and check the status of your request in the Approval state column:
    Approval state Record Remediation task
    Approved The State of the record transitions to Closed with Reason as False positive. The State of the remediation task transitions to Closed with Reason as False positive. The state is rolled down to the records in the remediation task accordingly.

    Navigate to the Details tab of a Remediation task and set the expiry date for false positive in the Until field if required. The remediation task reverts to the Open state after the specified date and the state is rolled down to the test results.

    Rejected The state of the record does not change. The state of the remediation task and its records reverts to previous state.

    In the Activity stream of a record or remediation task, you can view the entire workflow of the false positive request.