PT0-001 · Question #89
Which of the following BEST explains why it is important to maintain confidentiality of any identified findings when performing a penetration test?
The correct answer is D. Penetration test findings can assist an attacker in compromising a system. Penetration test findings document specific vulnerabilities and exploitation paths that, if disclosed to unauthorized parties, provide attackers with a direct roadmap to compromise the target organization.
Question
Which of the following BEST explains why it is important to maintain confidentiality of any identified findings when performing a penetration test?
Options
- APenetration test findings often contain company intellectual property
- BPenetration test findings could lead to consumer dissatisfaction if made pubic
- CPenetration test findings are legal documents containing privileged information
- DPenetration test findings can assist an attacker in compromising a system
How the community answered
(39 responses)- A3% (1)
- B5% (2)
- C3% (1)
- D90% (35)
Why each option
Penetration test findings document specific vulnerabilities and exploitation paths that, if disclosed to unauthorized parties, provide attackers with a direct roadmap to compromise the target organization.
While findings may reference proprietary systems, intellectual property protection is not the primary security rationale for confidentiality - the operational risk of enabling an attack is the core concern.
Consumer dissatisfaction is a reputational and business concern, not the technical security reason for keeping penetration test results confidential.
Penetration test reports are confidential business documents but are not legal documents and do not carry attorney-client or other formal legal privilege by default.
Penetration test reports detail exact vulnerabilities, misconfigurations, and exploitation techniques discovered during testing. If this information reaches a malicious actor, it removes the reconnaissance burden and gives them a precise blueprint for attacking the organization's systems without needing to perform their own discovery.
Concept tested: Penetration test confidentiality and responsible data handling
Source: https://www.comptia.org/training/resources/exam-objectives/comptia-pentest-plus-pt0-003-exam-objectives
Topics
Community Discussion
No community discussion yet for this question.