nerdexam
CompTIA

PT0-002 · Question #182

A final penetration test report has been submitted to the board for review and accepted. The report has three findings rated high. Which of the following should be the NEXT step?

The correct answer is B. Remediate the findings. After a penetration test report with high-rated findings is accepted, the immediate next step is to remediate those identified vulnerabilities. Remediation is crucial for addressing the weaknesses discovered and improving the organization's security posture.

Engagement management

Question

A final penetration test report has been submitted to the board for review and accepted. The report has three findings rated high. Which of the following should be the NEXT step?

Options

  • APerform a new penetration test.
  • BRemediate the findings.
  • CProvide the list of common vulnerabilities and exposures.
  • DBroaden the scope of the penetration test.

How the community answered

(62 responses)
  • A
    8% (5)
  • B
    76% (47)
  • C
    3% (2)
  • D
    13% (8)

Why each option

After a penetration test report with high-rated findings is accepted, the immediate next step is to remediate those identified vulnerabilities. Remediation is crucial for addressing the weaknesses discovered and improving the organization's security posture.

APerform a new penetration test.

Performing a new penetration test immediately is premature as the purpose of the first test was to identify weaknesses; the next step is to fix them before re-testing for verification.

BRemediate the findings.Correct

Once a penetration test report is accepted and high-rated findings are acknowledged, the immediate and most critical next step is to remediate the identified vulnerabilities. Remediation involves implementing fixes, patches, or configuration changes to eliminate or mitigate the security weaknesses discovered, thereby improving the organization's overall security posture.

CProvide the list of common vulnerabilities and exposures.

Providing a list of common vulnerabilities and exposures (CVEs) might be part of the report or remediation effort for context, but it is not the next action step itself; remediation is the direct action taken based on the findings.

DBroaden the scope of the penetration test.

Broadening the scope of the penetration test is inappropriate at this stage, as the current high-rated findings need to be addressed and verified within the existing scope before considering any expansion.

Concept tested: Penetration testing lifecycle - post-reporting

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf

Topics

#Remediation#Post-penetration testing#Vulnerability management#PenTest lifecycle

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice