Findings reporting, remediation recommendations, and post engagement communication concepts tested on the CompTIA PenTest+ exam.
29 cards · basic cards · AI-written, checked twice. Edit anything.
- What is the primary purpose of an executive summary in a penetration test report?
- To provide decision-makers with a high-level overview of findings, risks, and recommendations without technical details
- Define CVSS score
- A standardized vulnerability scoring system that rates severity on a scale of 0 to 10, with 10 being most critical
- Name three typical sections of a professional penetration test report
- Executive summary, findings and analysis, and recommendations
- What should a remediation recommendation include?
- Specific steps to fix the issue, resources required, and estimated time to remediate
- What is a proof of concept in pentest reporting?
- Evidence that demonstrates a vulnerability is exploitable and documents the steps taken to exploit it
- Define risk rating in penetration test reports
- A classification that combines likelihood of exploitation with business impact, typically Critical, High, Medium, or Low
- What is the difference between likelihood and impact in risk assessment?
- Likelihood is the probability an attack will occur; impact is the severity of consequences if it does occur
- What should pentest evidence include?
- Screenshots, logs, command output, and detailed descriptions of how findings were discovered
- What is the purpose of the findings section in a pentest report?
- To describe identified vulnerabilities, explain their significance, provide proof of concept, and recommend remediations
- What is stakeholder communication in penetration testing?
- The process of informing relevant parties including management, security teams, and IT staff about findings and next steps
- What activities should be included in the post-engagement phase?
- Delivering the report, clarifying findings, arranging follow-up testing, and verifying remediation efforts
- Why is follow-up testing important after a pentest?
- To verify that vulnerabilities have been properly remediated and no new issues were introduced
- What defines a critical finding in pentest reporting?
- A vulnerability that poses an immediate threat to the organization and requires urgent remediation
- Define a false positive in pentest reporting
- A reported vulnerability that does not actually exist or cannot be reliably exploited
- Why are clear recommendations essential in penetration test reports?
- They provide actionable steps to reduce risk and help management understand what needs to be fixed and why