nerdexam
CompTIA

PT0-002 · Question #434

Which of the following elements of a penetration testing report aims to provide a normalized and standardized representation of discovered vulnerabilities and the overall threat they present to an…

The correct answer is B. Vulnerability severity rating. The vulnerability severity rating element of a penetration testing report provides a normalized and standardized representation of discovered vulnerabilities and their threat levels. It typically involves assigning a numerical or categorical score (such as low, medium, high…

Reporting and Communication

Question

Which of the following elements of a penetration testing report aims to provide a normalized and standardized representation of discovered vulnerabilities and the overall threat they present to an affected system or network?

Options

  • AExecutive summary
  • BVulnerability severity rating
  • CRecommendations of mitigation
  • DMethodology

How the community answered

(63 responses)
  • A
    3% (2)
  • B
    94% (59)
  • C
    2% (1)
  • D
    2% (1)

Explanation

The vulnerability severity rating element of a penetration testing report provides a normalized and standardized representation of discovered vulnerabilities and their threat levels. It typically involves assigning a numerical or categorical score (such as low, medium, high, critical) to each vulnerability based on factors like exploitability, impact, and the context in which the vulnerability exists. This helps in prioritizing the vulnerabilities for remediation and provides a clear understanding of the risk they pose to the system or network.

Topics

#Penetration test reports#Vulnerability severity#Risk assessment#Reporting standards

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice