CSX Report Writing & Documentation 3 — Questions and Answers
Question 1: Which component should be included in the methodology section of a penetration test report?
- Attacker CVs and certifications
- Scope boundaries, testing phases, and tools used (Correct answer)
- Client billing information
- Future project proposals
Correct answer: Scope boundaries, testing phases, and tools used
The methodology section documents the testing approach including scope, phases, and tools so findings can be reproduced and validated.
Question 2: What is the purpose of a 'proof of concept' section in a vulnerability report?
- To showcase the tester's programming skills
- To demonstrate that the vulnerability is exploitable and reproducible (Correct answer)
- To provide source code for the client to reuse
- To estimate the cost of exploitation
Correct answer: To demonstrate that the vulnerability is exploitable and reproducible
A proof of concept demonstrates real exploitability, helping the client understand severity and prioritize remediation over theoretical risks.
Question 3: An analyst is documenting a phishing campaign. Which detail is LEAST important to include in the technical findings?
- Email headers and source IPs
- Malware payload hash values
- The attacker's presumed nationality (Correct answer)
- Affected user accounts
Correct answer: The attacker's presumed nationality
Attribution of nationality is speculative, often inaccurate, and not actionable; technical artifacts and affected assets are what drive remediation.
Question 4: Which report type is most appropriate for communicating ongoing security posture to a board of directors on a quarterly basis?
- Detailed technical vulnerability assessment
- Executive dashboard with KPIs and trend data (Correct answer)
- Raw log exports from SIEM
- Full forensic investigation report
Correct answer: Executive dashboard with KPIs and trend data
An executive dashboard with KPIs and trends translates security data into business-relevant metrics appropriate for board-level decision-making.
Question 5: What is the function of a 'findings register' in ongoing security program documentation?
- A log of employee security training completions
- A centralized tracking document for open, remediated, and accepted vulnerabilities (Correct answer)
- A list of approved security vendors
- A record of firewall rule changes
Correct answer: A centralized tracking document for open, remediated, and accepted vulnerabilities
A findings register maintains the lifecycle status of all identified vulnerabilities, enabling organizations to track remediation progress over time.
Question 6: When classifying data in a security report, which classification label typically requires the most restrictive handling?
- Public
- Internal Use Only
- Confidential
- Top Secret / Restricted (Correct answer)
Correct answer: Top Secret / Restricted
Top Secret or Restricted classifications impose the most stringent access controls, distribution limits, and handling procedures.
Question 7: What is 'residual risk' in the context of a security assessment report?
- Risk that existed before the assessment began
- Risk remaining after controls have been applied (Correct answer)
- Risk associated with the assessment process itself
- Risk transferred to a third party via insurance
Correct answer: Risk remaining after controls have been applied
Residual risk is what remains after mitigation controls are implemented, and it must be formally accepted by management or further reduced.
Which component should be included in the methodology section of a penetration test report?