exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 353 discussion

Actual exam question from CompTIA's PT0-002
Question #: 353
Topic #: 1
[All PT0-002 Questions]

An organization’s Chief Information Security Officer debates the validity of a critical finding from a penetration assessment that was completed six months ago. Which of the following post-report delivery activities would have most likely prevented this scenario?

  • A. Client acceptance
  • B. Data destruction process
  • C. Attestation of findings
  • D. Lessons learned
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ta2oo
Highly Voted 9 months, 4 weeks ago
Selected Answer: C
C is the correct answer. Attestation before Client acceptance.
upvoted 8 times
...
mat22
Highly Voted 10 months, 1 week ago
Correct answer is C. Attestation of findings is a process in which the client confirms and acknowledges the findings and recommendations presented in a penetration testing report
upvoted 7 times
kinny4000
4 months, 1 week ago
No thats Client Acceptance, attestation of findings is a formal confirmation that findings exist, a testament that binds the pentester to their report, but it does not necessarily involve client agreement.
upvoted 2 times
...
...
kinny4000
Most Recent 4 months, 1 week ago
Selected Answer: A
Client acceptance is the process where the client reviews, confirms, and agrees with the findings in the penetration test report. This process ensures that both parties acknowledge the validity of the findings at the time of the report's delivery. If this had been done properly, the CISO would not be debating the validity of the findings six months later.
upvoted 2 times
...
HiggsBoson_Level
6 months, 3 weeks ago
Selected Answer: A
Answer is A. From the Pentest+ (PT0-002) Study Guide: Gaining The Client's Acceptance After finishing your PenTest and writing the report, you should plan to have a discussion with the client about the findings in the report. During the formal hand-off process, you will need to get confirmation from the client that they agree that the testing is complete and that they accept your findings as presented in your report.
upvoted 3 times
...
Fart2023
7 months ago
Selected Answer: A
A = Job done everyone happy, C is I just got the report and I have questions. C can't happen 6 months after....
upvoted 1 times
...
fecffa8
7 months, 1 week ago
Selected Answer: B
Correction. The answer is B. Also from the cert master. Yes client acceptance is them agreeing with you. Attestation is the process of providing evidence that the findings detailed in the PenTest report are true. In other words, by signing off on the report given to the client, you are attesting that you believe the information and conclusions in the report are authentic. Attestation is perhaps the most significant component of gaining client acceptance, as the client must believe that what you have said about their people, processes, and technology is accurate. Many organizations will not simply trust your word that a particular vulnerability exists, even if you've built yourself a good reputation over the years. You must be prepared to prove what you claim. Proof can come in many forms, and those forms usually depend on the nature of what is being proven. For example, if you want to prove that you were able to break into a server holding sensitive data, you could present exfiltrated data to the client as proof.
upvoted 3 times
...
fecffa8
7 months, 1 week ago
Selected Answer: A
straight from the cert master Gaining The Client's Acceptance After finishing your PenTest and writing the report, you should plan to have a discussion with the client about the findings in the report. During the formal hand-off process, you will need to get confirmation from the client that they agree that the testing is complete and that they accept your findings as presented in your report. Use the meeting to discuss with the client anything that needs to be clarified or changed in the report before they can be confident in its conclusions. Gaining the client's acceptance is of paramount importance, as they will not automatically be satisfied with your report just because you have written one. They need to be convinced that the test was worthwhile from a business standpoint and that it truly met the objectives that were set out during the planning phase.
upvoted 2 times
...
ZoeAnneTaylor
8 months, 2 weeks ago
Selected Answer: A
Attestation is only for compliance/regulatory scans. Client acceptance is ... exactly what it sounds like - the client accepting the results. The client in the question did not accept the results of the engagement.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...