Reporting and Communication Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Reporting and Communication flashcards as text
What is a 'finding' in a penetration test report?
Answer: A documented vulnerability or security weakness discovered during testing, including evidence and impact
A finding is a documented security issue with evidence, severity rating, impact description, and remediation guidance included in the report.
Why is a penetration test report marked 'CONFIDENTIAL' or 'RESTRICTED'?
Answer: Because it contains a detailed roadmap of exploitable weaknesses that could be used by attackers if disclosed
A pentest report is a sensitive document because it details exactly how to compromise the client's systems; unauthorized disclosure could enable real attacks.
What should a tester do if they discover evidence of an active breach by a third party during a penetration test?
Answer: Immediately stop testing and notify the client so they can initiate incident response
Discovering an active breach requires immediate client notification so they can engage incident response; continuing to test could destroy forensic evidence.
In the context of penetration test reporting, what is 'risk rating' typically based on?
Answer: A combination of likelihood of exploitation and potential impact on the organization
Risk rating combines likelihood (how probable exploitation is) with impact (how severe the consequences would be) to produce a meaningful priority score.
A client's development team says they cannot reproduce a finding you documented. What should you do?
Answer: Provide additional technical detail, screenshots, or offer a live demonstration to help them reproduce it
Supporting the client in reproducing findings through additional evidence or walkthroughs ensures the vulnerability is properly understood and addressed.
Which element is essential to include when reporting a network-level vulnerability such as an open port exposing a vulnerable service?
Answer: IP address, port number, service version, CVE reference, and evidence of exploitability
Network vulnerability findings require precise technical identifiers — host, port, service, version, CVE — along with exploitation evidence so the team can locate and fix the issue.
What is the key difference between 'false positive' and 'false negative' in penetration test findings?
Answer: A false positive reports a vulnerability that does not actually exist; a false negative misses a real vulnerability
False positives waste remediation effort on non-issues, while false negatives leave real vulnerabilities undiscovered and unfixed — both reduce report quality.