
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 4
Report Writing and Post-Testing Actions CPENT Practice Questions (Page 4)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
52questions here
11free pages
10concepts
Questions 16–20
- 16
What is the purpose of a lessons-learned review after a penetration testing engagement?
Select an answer first - 17
You are assembling a penetration test report for a client. The report must include an executive summary, methodology, findings, and recommendations. The client also requested a separate section that lists all systems tested and the testing dates. Where should this information be placed in the report structure?
Select an answer first - 18
Which of the following is a recommended practice for formatting a professional penetration testing report?
Select an answer first - 19
During the client debriefing for a penetration test, the IT manager asks why a medium-severity finding was not fixed before the report was delivered, and the CISO asks for the top three actions to take next week. How should you handle the debriefing?
Select an answer first - 20
You are writing a penetration test report for a client that wants to use it to brief their security team and also share a version with their executives. Which report structure best serves both audiences?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.