PT0-002 · Question #41
Which of the following types of information should be included when writing the remediation section of a penetration test report to be viewed by the systems administrator and technical staff?
The correct answer is A. A quick description of the vulnerability and a high-level control to fix it. The remediation section of a penetration test report targeted at systems administrators and technical staff should contain a concise description of each vulnerability and actionable, technical guidance on how to fix it. Technical staff need concrete remediation steps they can…
Question
Which of the following types of information should be included when writing the remediation section of a penetration test report to be viewed by the systems administrator and technical staff?
Options
- AA quick description of the vulnerability and a high-level control to fix it
- BInformation regarding the business impact if compromised
- CThe executive summary and information regarding the testing company
- DThe rules of engagement from the assessment
How the community answered
(39 responses)- A90% (35)
- B3% (1)
- C5% (2)
- D3% (1)
Explanation
The remediation section of a penetration test report targeted at systems administrators and technical staff should contain a concise description of each vulnerability and actionable, technical guidance on how to fix it. Technical staff need concrete remediation steps they can implement - patch versions, configuration changes, code fixes, etc. Business impact information (B) belongs in the executive summary, not the technical remediation section. The executive summary and company information (C) are separate report sections. The rules of engagement (D) are scoping documents, not remediation guidance. Tailoring content to the audience is a core principle of professional pentest reporting.
Topics
Community Discussion
No community discussion yet for this question.