nerdexam
CompTIA

PT0-002 · Question #369

Penetration-testing activities have concluded, and the initial findings have been reviewed with the client. Which of the following best describes the NEXT step in the engagement?

The correct answer is C. Attestation of findings and delivery of the report. After initial findings are reviewed, the formal documentation of all discoveries, risk assessments, and recommendations is compiled into the final report, which is then formally delivered to the client. This report attests to the findings and serves as the official record of…

Reporting and Communication

Question

Penetration-testing activities have concluded, and the initial findings have been reviewed with the client. Which of the following best describes the NEXT step in the engagement?

Options

  • APerforming a live demonstration of the results to the system administrators
  • BScheduling of follow-up actions and retesting
  • CAttestation of findings and delivery of the report
  • DReview of the lessons during the engagement

How the community answered

(29 responses)
  • A
    14% (4)
  • B
    3% (1)
  • C
    76% (22)
  • D
    7% (2)

Why each option

After initial findings are reviewed, the formal documentation of all discoveries, risk assessments, and recommendations is compiled into the final report, which is then formally delivered to the client. This report attests to the findings and serves as the official record of the engagement.

APerforming a live demonstration of the results to the system administrators

A live demonstration might occur as part of initial findings review or final presentation, but it's not the next formal step after initial review; the report is the primary deliverable.

BScheduling of follow-up actions and retesting

Scheduling follow-up actions and retesting typically occurs after the final report has been delivered and the client has had time to implement remediations, not immediately after initial findings review.

CAttestation of findings and delivery of the reportCorrect

Following the initial review of findings, the next critical step is the formal attestation and delivery of the comprehensive penetration test report. This report details all vulnerabilities, their impact, and recommended remediations, serving as the official record for the client.

DReview of the lessons during the engagement

A review of lessons learned during the engagement (a post-mortem) is usually conducted internally by the penetration testing team or with the client much later, often after remediation and retesting, not as the immediate next step after initial findings review.

Concept tested: Penetration test engagement lifecycle - Post-testing phases

Topics

#Penetration Testing Lifecycle#Reporting#Client Communication#Engagement Close

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice