nerdexam
EC-Council

312-50V12 · Question #168

A large organization has recently performed a vulnerability assessment using Nessus Professional, and the security team is now preparing the final report. They have identified a high- risk…

The correct answer is A. Proof of concept (PoC) of the vulnerability, if possible, to demonstrate its potential impact on the. The question identifies what is typically excluded from the detailed documentation of a specific high-risk vulnerability in a vulnerability assessment report. The correct answer, a Proof of Concept (PoC) demonstrating exploitation, is often omitted from general reports due to…

Submitted by lars.no· Mar 4, 2026Information Security and Ethical Hacking Overview

Question

A large organization has recently performed a vulnerability assessment using Nessus Professional, and the security team is now preparing the final report. They have identified a high- risk vulnerability, named XYZ, which could potentially allow unauthorized access to the network. In preparing the report, which of the following elements would NOT be typically included in the detailed documentation for this specific vulnerability?

Options

  • AProof of concept (PoC) of the vulnerability, if possible, to demonstrate its potential impact on the
  • BThe total number of high, medium, and low-risk vulnerabilities detected throughout the network.
  • CThe list of all affected systems within the organization that are susceptible to the identified
  • DThe CVE ID of the vulnerability and its mapping to the vulnerability's name, XYZ.

How the community answered

(38 responses)
  • A
    76% (29)
  • B
    13% (5)
  • C
    8% (3)
  • D
    3% (1)

Why each option

The question identifies what is typically excluded from the detailed documentation of a specific high-risk vulnerability in a vulnerability assessment report. The correct answer, a Proof of Concept (PoC) demonstrating exploitation, is often omitted from general reports due to security risks.

AProof of concept (PoC) of the vulnerability, if possible, to demonstrate its potential impact on theCorrect

While evidence and impact of a Proof of Concept (PoC) are crucial for validating a high-risk vulnerability, the actual PoC code, scripts, or detailed exploitation steps are generally not included directly within the detailed documentation of a final assessment report. This is a security best practice to prevent the report from becoming an exploit blueprint if compromised, as it could provide unauthorized parties with a direct method to exploit the identified vulnerability.

BThe total number of high, medium, and low-risk vulnerabilities detected throughout the network.

The total number of high, medium, and low-risk vulnerabilities is a critical component of the overall vulnerability assessment report, typically found in the executive summary or aggregate findings section, which provides essential context for any specific vulnerability's severity and organizational risk, thus it is part of the comprehensive documentation.

CThe list of all affected systems within the organization that are susceptible to the identified

A comprehensive list of all affected systems susceptible to a specific vulnerability is a fundamental element required in its detailed documentation, enabling targeted remediation efforts and demonstrating the scope of the issue.

DThe CVE ID of the vulnerability and its mapping to the vulnerability's name, XYZ.

The CVE ID (Common Vulnerabilities and Exposures identifier) and its mapping to the vulnerability's name are essential for accurate identification, referencing, and cross-referencing with threat intelligence, making it a standard and critical inclusion in detailed vulnerability documentation.

Concept tested: Vulnerability assessment report components

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-vulnerability-management/tvm-vulnerability-report?view=o365-worldwide

Topics

#vulnerability assessment#Nessus#reporting#penetration testing lifecycle

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice