Certified Information Systems Security Professional CISSP · Free Practice Question Medium

Question 31

Your security team has completed a penetration test and identified several exploitable vulnerabilities. To ensure a comprehensive remediation plan, what should be included in the final report?
  • A The total number of vulnerabilities found, without details.
  • B A risk-based prioritization of vulnerabilities and recommended fixes.
  • C A list of vulnerabilities but no remediation recommendations.
  • D Only vulnerabilities that have been successfully exploited.
Reveal correct answer

Correct answer: B

Explanation

OBJ. 6.4 - A penetration test report should prioritize vulnerabilities based on risk and provide recommended fixes to ensure effective remediation. Reporting only the number of vulnerabilities or omitting remediation details fails to provide actionable insights. Excluding unexploited vulnerabilities may overlook critical issues. A well-structured report helps security teams focus on the most significant threats. For support or reporting issues, include Question ID: 67d96923531aa8d1859b24a9 in your ticket. Thank you.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need