PT0-002 · Question #524
Which of the following types of communication should a penetration tester provide a client to document test results for PCI DSS compliance?
The correct answer is C. Attestation of findings. PCI DSS (Payment Card Industry Data Security Standard) has specific compliance documentation requirements, and an Attestation of Findings (also called Attestation of Compliance) is the formal document used to certify that penetration testing was conducted and to record the…
Question
Which of the following types of communication should a penetration tester provide a client to document test results for PCI DSS compliance?
Options
- AExecutive summary
- BTesting methodology overview
- CAttestation of findings
- DRemediation plan
How the community answered
(19 responses)- B5% (1)
- C84% (16)
- D11% (2)
Explanation
PCI DSS (Payment Card Industry Data Security Standard) has specific compliance documentation requirements, and an Attestation of Findings (also called Attestation of Compliance) is the formal document used to certify that penetration testing was conducted and to record the results in a PCI DSS-compliant format. It is a legally and regulatory recognized record of the test. An executive summary (A) is too high-level and not a PCI DSS compliance artifact. A testing methodology overview (B) describes how the test was done but is not the required compliance document. A remediation plan (D) addresses fixing vulnerabilities but is not the document that attests to the test itself for compliance purposes.
Topics
Community Discussion
No community discussion yet for this question.