Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 7Objective 4

Report Writing and Post-Testing Actions CPENT Practice Questions (Page 3)

Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.

52questions here
11free pages
10concepts

Questions 11–15

  1. 11application · medium

    During a web application penetration test, you discovered a SQL injection vulnerability in a login form that allows authentication bypass, and a separate cross-site scripting (XSS) flaw that only affects a low-privilege user's session. The client's risk matrix rates likelihood and impact on a 1–5 scale. You assigned the SQL injection a likelihood of 4 and impact of 5, and the XSS a likelihood of 3 and impact of 2. How should you prioritize these findings in the report?

    Select an answer first
  2. 12expert · hard

    Your penetration test found a critical vulnerability in a legacy application that the client cannot patch because the vendor no longer supports it. The application is internet-facing and processes customer orders. The client asks for remediation recommendations that balance risk reduction with business continuity. What should you recommend?

    Select an answer first
  3. 13expert · hard

    You are writing the executive summary for a report where the client's board of directors will decide whether to fund a major security remediation program. The test found multiple critical vulnerabilities, but the client's security team has already remediated two of them during the testing window. The remaining critical issues require significant investment. How should the executive summary present the risk posture?

    Select an answer first
  4. 14expert · hard

    After a penetration test, your team identifies that the cleanup process was incomplete because the tester forgot to remove a temporary file that contained credentials. The client discovered the file and is concerned about residual risk. What is the most appropriate lesson-learned action?

    Select an answer first
  5. 15application · medium

    A penetration test found a critical vulnerability in a legacy system that cannot be patched because the vendor no longer supports it. The system is critical to business operations. What is the most appropriate remediation recommendation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.