
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 4
Report Writing and Post-Testing Actions CPENT Practice Questions (Page 5)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
52questions here
11free pages
10concepts
Questions 21–25
- 21
During a penetration test, you captured plaintext credentials, customer PII from a database, and internal network diagrams. You need to deliver the final report to the client. What is the most appropriate way to handle this sensitive data?
Select an answer first - 22
You are presenting the final penetration test report to the client's stakeholders, including the CISO, IT managers, and developers. The CISO asks why a critical finding was rated Critical when the exploit required physical access to a server room. How should you respond?
Select an answer first - 23
You are documenting a complex vulnerability chain: an attacker can exploit an SSRF in a web application to access an internal metadata service, obtain temporary credentials, and then use those credentials to access an internal database. The client's developers need to understand the full chain to remediate it. What is the most effective way to document this in the technical findings section?
Select an answer first - 24
You are writing an executive summary for a penetration test report. The test found a critical vulnerability that could allow an attacker to take over the entire network, and several low-severity issues. The client's executives are concerned about the cost of remediation. What should the executive summary include?
Select an answer first - 25
You are writing a penetration test report that includes a finding with screenshots showing sensitive data. The client has a policy that all reports must be encrypted when sent via email. What is the most appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.