nerdexam
CompTIA

PT0-002 · Question #445

An organization's Chief Information Security Officer debates the validity of a critical finding from a penetration assessment that was completed six months ago. Which of the following post-report…

The correct answer is A. Client acceptance. Client acceptance (A) is a critical post-report delivery activity that involves the client formally accepting the findings and conclusions of a penetration assessment report. This process usually includes a review of the findings by the client, discussions about the impact, and…

Reporting and Communication

Question

An organization's Chief Information Security Officer debates the validity of a critical finding from a penetration assessment that was completed six months ago. Which of the following post-report delivery activities would have most likely prevented this scenario?

Options

  • AClient acceptance
  • BData destruction process
  • CAttestation of findings
  • DLessons learned

How the community answered

(38 responses)
  • A
    79% (30)
  • B
    5% (2)
  • C
    3% (1)
  • D
    13% (5)

Explanation

Client acceptance (A) is a critical post-report delivery activity that involves the client formally accepting the findings and conclusions of a penetration assessment report. This process usually includes a review of the findings by the client, discussions about the impact, and agreement on the accuracy and relevance of the reported vulnerabilities and issues. Ensuring client acceptance soon after the delivery of the report can prevent scenarios where the validity of findings is debated long after the assessment, as in the case described.

Topics

#Post-report activities#Client acceptance#Engagement closure#Report communication

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice