
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 4
Report Writing and Post-Testing Actions CPENT Practice Questions (Page 7)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
52questions here
11free pages
10concepts
Questions 31–35
- 31
Which section of a penetration testing report is primarily intended to provide a high-level overview of the engagement's purpose, scope, and overall risk posture for senior management?
Select an answer first - 32
What is the main purpose of including evidence (e.g., screenshots, logs) in the technical findings section of a penetration testing report?
Select an answer first - 33
When writing an executive summary for a penetration testing report, which of the following is most appropriate to include?
Select an answer first - 34
You are documenting a critical vulnerability found during a penetration test: an unauthenticated attacker can upload arbitrary files to a web application, leading to remote code execution. For the technical findings section, which set of details is most appropriate to include?
Select an answer first - 35
You are prioritizing findings for a penetration test report. The client's risk appetite is low, and they are particularly concerned about regulatory compliance. You found a medium-severity vulnerability that directly violates a compliance requirement, and a high-severity vulnerability that does not affect compliance. How should you prioritize these findings in the report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.