Reporting and Communication Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Reporting and Communication flashcards as text
What is the primary purpose of an executive summary in a penetration test report?
Answer: To provide a high-level overview of findings for non-technical stakeholders
The executive summary communicates risk and business impact at a level appropriate for management and executives who may not have technical backgrounds.
During a penetration test, you discover a critical vulnerability. The client's system admin is not available. What is the correct communication action?
Answer: Escalate immediately to the designated point of contact per the rules of engagement
Rules of engagement typically define escalation paths for critical findings; following this path ensures timely client awareness and proper authorization.
Which section of a penetration test report would contain step-by-step reproduction instructions for a SQL injection finding?
Answer: Technical Findings / Vulnerability Details
Technical findings sections include proof-of-concept steps, screenshots, and payloads so the client's team can reproduce and verify the vulnerability.
What does 'scope creep' mean in the context of a penetration test engagement?
Answer: Testing systems or assets not explicitly authorized in the rules of engagement
Scope creep refers to testing beyond the agreed boundaries, which can create legal and contractual issues for both the tester and client.
A penetration tester rates a vulnerability as 'High' severity. Which factor most directly influences this severity rating?
Answer: The combination of exploitability and potential business impact
Severity ratings consider both how easily a vulnerability can be exploited and what damage successful exploitation would cause to the organization.
What is the correct way to handle sensitive client data (e.g., captured credentials) discovered during a penetration test?
Answer: Securely document them in the report and delete all copies after delivery per the contract
Ethical handling requires securing discovered data, reporting it appropriately, and disposing of it according to contractual and legal obligations.
In a penetration test report, what does a 'proof of concept' (PoC) typically include?
Answer: Screenshots, commands, or code that demonstrates the vulnerability is exploitable
A PoC provides reproducible evidence — such as screenshots, tool output, or exploit code — proving that a vulnerability is real and exploitable.