PT0-002 · Question #474
Which of the following components should a penetration tester most likely include in a report at the end of an assessment?
The correct answer is A. Metrics and measures. A penetration tester should most likely include metrics and measures in a report at the end of an assessment. Metrics and measures provide quantitative data that helps in understanding the extent and impact of vulnerabilities found during the assessment. They offer a clear and…
Question
Which of the following components should a penetration tester most likely include in a report at the end of an assessment?
Options
- AMetrics and measures
- BClient interviews
- CCompliance information
- DBusiness policies
How the community answered
(22 responses)- A91% (20)
- C5% (1)
- D5% (1)
Explanation
A penetration tester should most likely include metrics and measures in a report at the end of an assessment. Metrics and measures provide quantitative data that helps in understanding the extent and impact of vulnerabilities found during the assessment. They offer a clear and objective way to convey the results and the effectiveness of the security controls in place. This data-driven approach aids in prioritizing remediation efforts, benchmarking against industry standards, and demonstrating improvements over time.
Topics
Community Discussion
No community discussion yet for this question.