ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 396 - PT0-002 discussion

Report
Export

An organization's Chief Information Security Officer debates the validity of a critical finding from a penetration assessment that was completed six months ago. Which of the following post-report delivery activities would have most likely prevented this scenario?

A.
Client acceptance
Answers
A.
Client acceptance
B.
Data destruction process
Answers
B.
Data destruction process
C.
Attestation of findings
Answers
C.
Attestation of findings
D.
Lessons learned
Answers
D.
Lessons learned
Suggested answer: A

Explanation:

Client acceptance (A) is a critical post-report delivery activity that involves the client formally accepting the findings and conclusions of a penetration assessment report. This process usually includes a review of the findings by the client, discussions about the impact, and agreement on the accuracy and relevance of the reported vulnerabilities and issues. Ensuring client acceptance soon after the delivery of the report can prevent scenarios where the validity of findings is debated long after the assessment, as in the case described.

Data destruction process (B), attestation of findings (C), and lessons learned (D) are also important aspects of a penetration testing engagement, but they do not directly address the issue of the client disputing the findings well after the report has been delivered. Client acceptance ensures both parties are in agreement on the outcomes of the assessment, minimizing disputes about the findings later on.

asked 02/10/2024
Sullivan Dabireau
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first