PT0-002 · Question #429
Which of the following describes how a penetration tester could prioritize findings in a report?
The correct answer is D. Cyberthreats. A penetration tester could prioritize findings in a report based on cyberthreats, specifically by assessing the likelihood of exploitation and the potential impact of a vulnerability when combined with known threat actor capabilities and attack vectors. This approach helps…
Question
Which of the following describes how a penetration tester could prioritize findings in a report?
Options
- ABusiness mission and goals
- BCyberassets
- CNetwork infrastructure
- DCyberthreats
How the community answered
(20 responses)- A5% (1)
- C5% (1)
- D90% (18)
Why each option
A penetration tester could prioritize findings in a report based on cyberthreats, specifically by assessing the likelihood of exploitation and the potential impact of a vulnerability when combined with known threat actor capabilities and attack vectors. This approach helps align remediation efforts with the most critical risks.
While business mission and goals influence the overall risk appetite, they don't directly provide a metric for prioritizing individual technical findings in a report, which require a more granular risk assessment.
Prioritizing findings solely based on cyberassets (e.g., valuing an asset highly) is insufficient without considering the specific vulnerabilities present on those assets and the active threats targeting them.
Network infrastructure is the target of the penetration test, but it does not, by itself, serve as a prioritization scheme for findings; the risk associated with vulnerabilities found within the infrastructure dictates prioritization.
Prioritizing findings in a penetration test report should consider the actual cyberthreats an organization faces, including the likelihood of a vulnerability being exploited by known threat actors and the potential impact of such an exploitation. By aligning findings with specific threat landscapes and intelligence, the most critical vulnerabilities that pose the greatest risk can be addressed first.
Concept tested: Penetration testing report prioritization
Topics
Community Discussion
No community discussion yet for this question.