nerdexam
CompTIA

PT0-001 · Question #138

A company performed an annual penetration test of its environment. In addition to several new findings, all of the previously identified findings persisted on the latest report. Which of the…

The correct answer is C. The organization is not taking action to remediate identified findings. When all previously identified findings reappear in a follow-up penetration test, it indicates the organization failed to act on the remediation recommendations from the prior engagement.

Engagement management

Question

A company performed an annual penetration test of its environment. In addition to several new findings, all of the previously identified findings persisted on the latest report. Which of the following is the MOST likely reason?

Options

  • AInfrastructure is being replaced with similar hardware and software.
  • BSystems administrators are applying the wrong patches.
  • CThe organization is not taking action to remediate identified findings.
  • DThe penetration testing tools were misconfigured.

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    7% (4)
  • C
    87% (47)
  • D
    4% (2)

Why each option

When all previously identified findings reappear in a follow-up penetration test, it indicates the organization failed to act on the remediation recommendations from the prior engagement.

AInfrastructure is being replaced with similar hardware and software.

Replacing infrastructure with similar hardware and software might reintroduce some vulnerabilities, but it would not explain why all prior findings persist identically across an annual test.

BSystems administrators are applying the wrong patches.

Applying wrong patches could leave some vulnerabilities open, but it is a specific technical error that would not account for every single previously identified finding remaining unaddressed.

CThe organization is not taking action to remediate identified findings.Correct

If every prior finding persists unchanged across an annual test cycle, the most direct explanation is that the organization did not prioritize or execute remediation of those vulnerabilities. Remediation requires deliberate action such as patching, configuration changes, or architectural fixes, and without it, the same weaknesses will be rediscovered every cycle. This reflects a process or prioritization failure rather than a technical one.

DThe penetration testing tools were misconfigured.

Misconfigured penetration testing tools would more likely produce inaccurate or incomplete results, not a consistent reproduction of all prior findings.

Concept tested: Penetration test remediation lifecycle and accountability

Source: https://www.nist.gov/publications/technical-guide-information-security-testing-and-assessment

Topics

#remediation tracking#pentest findings#risk management#annual assessment

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice