PT0-002 · Question #492
A penetration tester keeps a running diary of the day-to-day engagement activity. Which of the following is the most likely explanation for keeping the diary?
The correct answer is B. To monitor lessons learned. A penetration tester keeps a daily diary of engagement activity primarily to record experiences, challenges, and successful techniques to extract and monitor lessons learned for continuous improvement.
Question
A penetration tester keeps a running diary of the day-to-day engagement activity. Which of the following is the most likely explanation for keeping the diary?
Options
- ATo facilitate post-engagement cleanup
- BTo monitor lessons learned
- CTo foster client acceptance
- DTo follow the data destruction process
How the community answered
(33 responses)- A3% (1)
- B94% (31)
- C3% (1)
Why each option
A penetration tester keeps a daily diary of engagement activity primarily to record experiences, challenges, and successful techniques to extract and monitor lessons learned for continuous improvement.
While a diary might indirectly help track changes for cleanup, its main purpose is not to facilitate post-engagement cleanup, which usually involves specific procedures for tool removal and configuration reversal.
A daily diary serves as a valuable record for a penetration tester to document their actions, observations, effective methodologies, and any unforeseen issues encountered during an engagement. This detailed log is essential for post-engagement analysis, enabling the identification of lessons learned that can improve future testing strategies and personal skill development.
Fostering client acceptance is primarily achieved through clear communication, adherence to scope, professional conduct, and a comprehensive final report, not through the tester's internal daily notes.
Following the data destruction process is a formal procedural step after an engagement, and while documented in reports, it is not the primary reason for maintaining a day-to-day activity diary.
Concept tested: Penetration testing methodology - documentation and lessons learned
Source: https://owasp.org/www-project-penetration-testing-methodologies/
Topics
Community Discussion
No community discussion yet for this question.