โ† All EJPT Flashcard Decks

Reporting and Communication Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Reporting and Communication flashcards as text
  1. Which document formally defines the legal boundaries and authorization for a penetration test?

    Answer: The rules of engagement (RoE) / statement of work

    The rules of engagement or statement of work legally authorizes the test, defines scope, timing, and allowed techniques, protecting both parties.

  2. When communicating findings verbally during a debriefing, what should a penetration tester prioritize for a mixed technical and executive audience?

    Answer: Leading with business risk and impact before diving into technical details

    Mixed audiences require starting with business impact so executives understand risk, then providing technical depth for the engineering team.

  3. What is the main difference between a vulnerability assessment report and a penetration test report?

    Answer: A penetration test report includes active exploitation evidence, while a vulnerability assessment only identifies potential weaknesses

    Penetration test reports document actual exploitation chains and confirmed impact, whereas vulnerability assessments list identified weaknesses without necessarily exploiting them.

  4. A client asks you to remove a high-severity finding from the final report because it is embarrassing. What should you do?

    Answer: Decline and explain that accurate reporting is essential for their security improvement

    Altering or omitting findings compromises the integrity of the report and may expose the client to continued risk; professional ethics require accurate reporting.

  5. What is the purpose of including a 'remediation' or 'recommendation' section in a penetration test report?

    Answer: To provide actionable steps the client can take to fix identified vulnerabilities

    Remediation recommendations give the client a clear path to fixing vulnerabilities, turning the report from a problem list into an actionable security improvement plan.

  6. During a black-box penetration test engagement, the tester unexpectedly gains domain admin access. What is the appropriate next step?

    Answer: Immediately notify the client contact and pause or continue per the agreed escalation procedure

    Gaining domain admin is a critical milestone that should trigger immediate client notification per the rules of engagement to ensure proper oversight.

  7. Which CVSS metric group assesses how the vulnerability affects systems beyond the directly vulnerable component?

    Answer: Base Score - Scope

    The Scope metric in CVSS Base Score indicates whether exploitation can impact components beyond the vulnerable component's authorization scope.