nerdexam
CompTIA

PT0-002 · Question #233

Which of the following are the MOST important items for prioritizing fixes that should be included in the final report for a penetration test? (Choose two.)

The correct answer is B. The network location of the vulnerable device C. The vulnerability identifier. Prioritizing fixes in a penetration test report relies heavily on understanding the network exposure of the vulnerable device and the specific nature or identifier of the vulnerability.

Reporting and Communication

Question

Which of the following are the MOST important items for prioritizing fixes that should be included in the final report for a penetration test? (Choose two.)

Options

  • AThe CVSS score of the finding
  • BThe network location of the vulnerable device
  • CThe vulnerability identifier
  • DThe client acceptance form
  • EThe name of the person who found the flaw
  • FThe tool used to find the issue

How the community answered

(44 responses)
  • A
    16% (7)
  • B
    70% (31)
  • D
    7% (3)
  • E
    5% (2)
  • F
    2% (1)

Why each option

Prioritizing fixes in a penetration test report relies heavily on understanding the network exposure of the vulnerable device and the specific nature or identifier of the vulnerability.

AThe CVSS score of the finding

While the CVSS score provides a standardized severity metric, it is often a numerical representation derived from factors like impact and exploitability, which are better understood by the specific vulnerability identifier itself, and does not account for environmental factors like network location.

BThe network location of the vulnerable deviceCorrect

The network location of the vulnerable device is critical for prioritization as it determines the level of exposure to potential attackers, with internet-facing systems or those in highly sensitive network segments requiring more immediate attention.

CThe vulnerability identifierCorrect

The vulnerability identifier (e.g., CVE ID or a specific flaw type like SQL injection) provides crucial context about the nature, severity, and potential impact of the flaw, enabling informed prioritization based on known risks and exploitability.

DThe client acceptance form

The client acceptance form is an administrative document confirming the scope and terms of the engagement, not a factor for technical prioritization of fixes.

EThe name of the person who found the flaw

The identity of the person who found the flaw is irrelevant to the technical severity or prioritization of the vulnerability.

FThe tool used to find the issue

The tool used to find the issue provides context but does not directly influence the priority of remediation for a discovered vulnerability.

Concept tested: Penetration test report prioritization criteria

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf

Topics

#Vulnerability Prioritization#Penetration Test Reporting#Risk Assessment#Remediation Planning

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice