
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 4
Report Writing and Post-Testing Actions CPENT Practice Questions (Page 8)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
52questions here
11free pages
10concepts
Questions 36–40
- 36
What is the main objective of a client debriefing after a penetration testing engagement?
Select an answer first - 37
What is the primary goal of post-testing cleanup in a penetration testing engagement?
Select an answer first - 38
After completing a penetration test, you review the engagement and notice that the team spent excessive time manually verifying vulnerabilities that could have been automated, and one tester accidentally left a test file on a client server that was only discovered during cleanup. What should you document in the lessons-learned section of your internal post-engagement review?
Select an answer first - 39
After completing a penetration test, your team reviews the engagement and notes that the client's change-management process was not followed when you requested firewall rule changes, causing a delay. What is the most appropriate lesson-learned action?
Select an answer first - 40
You are preparing a penetration test report that will be reviewed by both the client's technical team and external auditors. The auditors require traceability between each finding and the evidence supporting it. The technical team needs to quickly identify which systems are affected. How should you structure the report to satisfy both requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.