GPEN · Question #403
The resulting business impact, of the penetration test or ethical hacking engagement is explained in what section of the final report?
The correct answer is D. Executive Summary. The Executive Summary section of a penetration test report is where business impact is communicated in non-technical language to management and executives.
Question
The resulting business impact, of the penetration test or ethical hacking engagement is explained in what section of the final report?
Options
- AProblems
- BFindings
- CImpact Assessment
- DExecutive Summary
How the community answered
(64 responses)- A8% (5)
- B14% (9)
- C3% (2)
- D75% (48)
Why each option
The Executive Summary section of a penetration test report is where business impact is communicated in non-technical language to management and executives.
The Problems section enumerates specific technical issues discovered during testing and does not translate those issues into business-level consequences.
The Findings section provides detailed technical descriptions of vulnerabilities, proof-of-concept steps, and affected systems - not a business impact analysis.
Impact Assessment is not a standard standalone section in widely accepted penetration testing report frameworks; business impact is formally addressed in the Executive Summary.
The Executive Summary is written specifically for senior management and non-technical stakeholders who need to understand the business consequences of the engagement without reading technical details. It describes the overall risk posture, potential financial and operational impact, and high-level recommendations - making it the appropriate section for business impact communication.
Concept tested: Penetration test report structure - executive summary purpose
Source: https://www.pentest-standard.org/index.php/Reporting
Topics
Community Discussion
No community discussion yet for this question.