nerdexam
CompTIA

PT0-002 · Question #429

Which of the following describes how a penetration tester could prioritize findings in a report?

The correct answer is D. Cyberthreats. A penetration tester could prioritize findings in a report based on cyberthreats, specifically by assessing the likelihood of exploitation and the potential impact of a vulnerability when combined with known threat actor capabilities and attack vectors. This approach helps…

Reporting and Communication

Question

Which of the following describes how a penetration tester could prioritize findings in a report?

Options

  • ABusiness mission and goals
  • BCyberassets
  • CNetwork infrastructure
  • DCyberthreats

How the community answered

(20 responses)
  • A
    5% (1)
  • C
    5% (1)
  • D
    90% (18)

Why each option

A penetration tester could prioritize findings in a report based on cyberthreats, specifically by assessing the likelihood of exploitation and the potential impact of a vulnerability when combined with known threat actor capabilities and attack vectors. This approach helps align remediation efforts with the most critical risks.

ABusiness mission and goals

While business mission and goals influence the overall risk appetite, they don't directly provide a metric for prioritizing individual technical findings in a report, which require a more granular risk assessment.

BCyberassets

Prioritizing findings solely based on cyberassets (e.g., valuing an asset highly) is insufficient without considering the specific vulnerabilities present on those assets and the active threats targeting them.

CNetwork infrastructure

Network infrastructure is the target of the penetration test, but it does not, by itself, serve as a prioritization scheme for findings; the risk associated with vulnerabilities found within the infrastructure dictates prioritization.

DCyberthreatsCorrect

Prioritizing findings in a penetration test report should consider the actual cyberthreats an organization faces, including the likelihood of a vulnerability being exploited by known threat actors and the potential impact of such an exploitation. By aligning findings with specific threat landscapes and intelligence, the most critical vulnerabilities that pose the greatest risk can be addressed first.

Concept tested: Penetration testing report prioritization

Topics

#Findings prioritization#Reporting#Cyberthreats#Risk assessment

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice