nerdexam
CompTIA

PT0-002 · Question #524

Which of the following types of communication should a penetration tester provide a client to document test results for PCI DSS compliance?

The correct answer is C. Attestation of findings. PCI DSS (Payment Card Industry Data Security Standard) has specific compliance documentation requirements, and an Attestation of Findings (also called Attestation of Compliance) is the formal document used to certify that penetration testing was conducted and to record the…

Reporting and Communication

Question

Which of the following types of communication should a penetration tester provide a client to document test results for PCI DSS compliance?

Options

  • AExecutive summary
  • BTesting methodology overview
  • CAttestation of findings
  • DRemediation plan

How the community answered

(19 responses)
  • B
    5% (1)
  • C
    84% (16)
  • D
    11% (2)

Explanation

PCI DSS (Payment Card Industry Data Security Standard) has specific compliance documentation requirements, and an Attestation of Findings (also called Attestation of Compliance) is the formal document used to certify that penetration testing was conducted and to record the results in a PCI DSS-compliant format. It is a legally and regulatory recognized record of the test. An executive summary (A) is too high-level and not a PCI DSS compliance artifact. A testing methodology overview (B) describes how the test was done but is not the required compliance document. A remediation plan (D) addresses fixing vulnerabilities but is not the document that attests to the test itself for compliance purposes.

Topics

#PCI DSS compliance#Reporting#Attestation#Documentation

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice