nerdexam
CompTIA

PT0-001 · Question #227

A penetration tester used an ASP.NET web shell to gain access to a web application, which allowed the tester to pivot in the corporate network. Which of the following is the MOST important follow-up…

The correct answer is E. Presenting attestation of findings. After delivering a penetration test report, presenting attestation of findings is the most critical step because it formally documents that all discovered vulnerabilities were disclosed and acknowledged by the client.

Engagement management

Question

A penetration tester used an ASP.NET web shell to gain access to a web application, which allowed the tester to pivot in the corporate network. Which of the following is the MOST important follow-up activity to complete after the tester delivers the report?

Options

  • ARemoving shells
  • BObtaining client acceptance
  • CRemoving tester-created credentials
  • DDocumenting lessons learned
  • EPresenting attestation of findings

How the community answered

(46 responses)
  • A
    9% (4)
  • B
    4% (2)
  • C
    13% (6)
  • D
    2% (1)
  • E
    72% (33)

Why each option

After delivering a penetration test report, presenting attestation of findings is the most critical step because it formally documents that all discovered vulnerabilities were disclosed and acknowledged by the client.

ARemoving shells

Removing shells is a critical cleanup task but should be completed before or during report delivery, not positioned as the primary follow-up after the report has already been submitted.

BObtaining client acceptance

Obtaining client acceptance is part of the close-out process but is formalized through the attestation of findings, making it a component of option E rather than a separate follow-up priority.

CRemoving tester-created credentials

Removing tester-created credentials is important for operational cleanup but, like shell removal, should occur before or alongside report delivery rather than as the chief post-report activity.

DDocumenting lessons learned

Documenting lessons learned is a valuable internal improvement exercise for the testing team but does not fulfill the client-facing obligation that attestation of findings addresses.

EPresenting attestation of findingsCorrect

Attestation of findings is a signed declaration confirming that the penetration tester has accurately reported all discovered vulnerabilities and that the client has received and acknowledged them. This document formally closes the engagement and provides legal protection for both parties, particularly important when invasive artifacts like the ASP.NET web shell used for pivoting were deployed. Without attestation, there is no documented proof that sensitive findings were properly communicated and accepted by the authorizing organization.

Concept tested: Post-engagement attestation of findings in pentesting

Topics

#attestation#post-engagement#report delivery#engagement closure

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice