nerdexam
CompTIA

PT0-001 · Question #229

A client's systems administrator requests a copy of the report from the penetration tester, but the systems administrator is not listed as a point of contact or signatory. Which of the following is…

The correct answer is C. Reply and explain to the systems administrator that proper authorization is needed to provide the. Penetration test reports contain sensitive vulnerability data that must only be distributed to parties authorized in the Rules of Engagement - the tester must inform the requester directly that proper authorization is required.

Engagement management

Question

A client's systems administrator requests a copy of the report from the penetration tester, but the systems administrator is not listed as a point of contact or signatory. Which of the following is the penetration tester's BEST course of action?

Options

  • ASend the report since the systems administrator will be in charge of implementing the fixes.
  • BSend the report and carbon copy the point of contact/signatory for visibility.
  • CReply and explain to the systems administrator that proper authorization is needed to provide the
  • DForward the request to the point of contact/signatory for authorization.

How the community answered

(28 responses)
  • B
    4% (1)
  • C
    93% (26)
  • D
    4% (1)

Why each option

Penetration test reports contain sensitive vulnerability data that must only be distributed to parties authorized in the Rules of Engagement - the tester must inform the requester directly that proper authorization is required.

ASend the report since the systems administrator will be in charge of implementing the fixes.

Sending the report based solely on operational role violates the confidentiality controls defined in the engagement contract, regardless of what the recipient intends to do with it.

BSend the report and carbon copy the point of contact/signatory for visibility.

Carbon-copying the point of contact does not constitute prior authorization - the report would still be delivered to an unauthorized party before approval is granted.

CReply and explain to the systems administrator that proper authorization is needed to provide theCorrect

The Rules of Engagement and Statement of Work define exactly who is authorized to receive deliverables such as the penetration test report. Since the systems administrator is not listed as a point of contact or signatory, sharing the report without authorization would violate the confidentiality terms of the engagement. Directly informing the requester of the authorization requirement is the most transparent and professionally responsible course of action.

DForward the request to the point of contact/signatory for authorization.

Forwarding the request without informing the requester is less direct and leaves the systems administrator without guidance on what authorization steps are actually required.

Concept tested: Pentest report handling and authorization controls

Source: https://www.comptia.org/content/guides/comptia-pentest-exam-objectives

Topics

#report distribution#authorization#confidentiality#engagement management

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice