nerdexam
CompTIA

PT0-001 · Question #121

A penetration test was performed by an on-staff technicians junior technician. During the test, the technician discovered the application could disclose an SQL table with user account and password…

The correct answer is D. Request that management create an RFP to begin a formal engagement with a professional. In this scenario, since the testing was performed by an on-staff junior administrator, it may be in the company’s best interest to create a request for proposal (RFP) from a professional penetration testing company to agree with the assessments and to give the company any…

Engagement management

Question

A penetration test was performed by an on-staff technicians junior technician. During the test, the technician discovered the application could disclose an SQL table with user account and password information. Which of the following is the MOST effective way to notify management of this finding and its importance?

Options

  • ADocument Ihe findtngs with an executive summary, recommendations, and screenshots of the
  • BConnect to the SQL server using this information and change the password to one or two non-
  • CNotify the development team of the discovery and suggest that input validation be implemented
  • DRequest that management create an RFP to begin a formal engagement with a professional

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    10% (3)
  • C
    3% (1)
  • D
    80% (24)

Explanation

In this scenario, since the testing was performed by an on-staff junior administrator, it may be in the company’s best interest to create a request for proposal (RFP) from a professional penetration testing company to agree with the assessments and to give the company any vulnerability findings. An RFP is a document that solicits proposal, often made through a bidding

Topics

#SQL disclosure#findings reporting#executive summary#engagement communication

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice