Reporting and Communication Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Reporting and Communication flashcards as text
Which document formally defines the legal boundaries and authorization for a penetration test?
Answer: The rules of engagement (RoE) / statement of work
The rules of engagement or statement of work legally authorizes the test, defines scope, timing, and allowed techniques, protecting both parties.
When communicating findings verbally during a debriefing, what should a penetration tester prioritize for a mixed technical and executive audience?
Answer: Leading with business risk and impact before diving into technical details
Mixed audiences require starting with business impact so executives understand risk, then providing technical depth for the engineering team.
What is the main difference between a vulnerability assessment report and a penetration test report?
Answer: A penetration test report includes active exploitation evidence, while a vulnerability assessment only identifies potential weaknesses
Penetration test reports document actual exploitation chains and confirmed impact, whereas vulnerability assessments list identified weaknesses without necessarily exploiting them.
A client asks you to remove a high-severity finding from the final report because it is embarrassing. What should you do?
Answer: Decline and explain that accurate reporting is essential for their security improvement
Altering or omitting findings compromises the integrity of the report and may expose the client to continued risk; professional ethics require accurate reporting.
What is the purpose of including a 'remediation' or 'recommendation' section in a penetration test report?
Answer: To provide actionable steps the client can take to fix identified vulnerabilities
Remediation recommendations give the client a clear path to fixing vulnerabilities, turning the report from a problem list into an actionable security improvement plan.
During a black-box penetration test engagement, the tester unexpectedly gains domain admin access. What is the appropriate next step?
Answer: Immediately notify the client contact and pause or continue per the agreed escalation procedure
Gaining domain admin is a critical milestone that should trigger immediate client notification per the rules of engagement to ensure proper oversight.
Which CVSS metric group assesses how the vulnerability affects systems beyond the directly vulnerable component?
Answer: Base Score - Scope
The Scope metric in CVSS Base Score indicates whether exploitation can impact components beyond the vulnerable component's authorization scope.