โ† All EJPT Flashcard Decks

Reporting and Communication Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Reporting and Communication flashcards as text
  1. Why should penetration testers maintain detailed notes and logs throughout the engagement?

    Answer: To support accurate reporting, provide evidence for findings, and enable recreation of the testing timeline if disputed

    Detailed logs and notes form the evidentiary basis for the final report and protect the tester legally if the engagement or its findings are ever questioned.

  2. Which of the following best describes 'remediation verification' in the context of penetration testing?

    Answer: A follow-up assessment to confirm that reported vulnerabilities have been successfully fixed

    Remediation verification (also called retesting) confirms that the client's fixes actually close the vulnerabilities identified in the original penetration test.

  3. A tester's automated scanner reports 200 vulnerabilities. What is the professional approach before including these in the final report?

    Answer: Manually validate each finding to eliminate false positives before reporting

    Automated scanner output must be manually validated because scanners produce false positives; reporting unvalidated results wastes client remediation resources.

  4. What does 'attack narrative' or 'attack chain' in a penetration test report describe?

    Answer: A chronological story showing how individual vulnerabilities were chained together to achieve a significant compromise

    An attack narrative shows how low-to-medium findings can be combined into a realistic attack path, helping clients understand compounded risk beyond individual vulnerabilities.

  5. Which of the following is a key characteristic of a well-written vulnerability description in a penetration test report?

    Answer: Clear, concise language that explains what the vulnerability is, why it matters, and how it was confirmed

    Effective vulnerability descriptions use accessible language tied to the client's specific environment, combining technical accuracy with business context.

  6. What is the purpose of including a 'scope' section in a penetration test report?

    Answer: To clearly define what systems, networks, and applications were tested so the reader understands the coverage and limitations

    The scope section establishes the boundaries of the assessment so stakeholders understand what was tested, what was excluded, and where risk may still exist outside tested areas.

  7. After delivering a penetration test report, the client asks you to sign an NDA retroactively. What is the professional best practice?

    Answer: Insist that NDAs and confidentiality terms should always be agreed upon and signed before the engagement begins

    NDAs and confidentiality agreements should be established before testing begins to protect client data throughout the entire engagement, not just after delivery.