Certified Information Systems Security Professional CISSP · Free Practice Question Medium
Question 31
Your security team has completed a penetration test and identified several exploitable vulnerabilities. To ensure a comprehensive remediation plan, what should be included in the final report?
- A The total number of vulnerabilities found, without details.
- B A risk-based prioritization of vulnerabilities and recommended fixes.
- C A list of vulnerabilities but no remediation recommendations.
- D Only vulnerabilities that have been successfully exploited.
Reveal correct answer
Correct answer: B
Explanation
OBJ. 6.4 - A penetration test report should prioritize vulnerabilities based on risk and provide recommended fixes to ensure effective remediation. Reporting only the number of vulnerabilities or omitting remediation details fails to provide actionable insights. Excluding unexploited vulnerabilities may overlook critical issues. A well-structured report helps security teams focus on the most significant threats. For support or reporting issues, include Question ID: 67d96923531aa8d1859b24a9 in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
