
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 4
Report Writing and Post-Testing Actions CPENT Practice Questions (Page 9)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
52questions here
11free pages
10concepts
Questions 41–45
- 41
After completing a penetration test, you discover that a tester left an SSH key on a compromised server that was used for persistence. The tester is on vacation and cannot be reached. The client's server is critical to production and cannot be taken offline. What is the most appropriate cleanup action?
Select an answer first - 42
You are preparing a penetration test report for a client that will be audited by an external regulator. The regulator requires that the report clearly show the testing scope, methodology, and evidence for each finding. The client also wants the report to be concise for internal distribution. How should you format the report?
Select an answer first - 43
Your penetration test identified a critical SQL injection vulnerability in a customer-facing application and a low-severity information disclosure in an internal tool. The client has limited development resources this quarter. What is the most appropriate remediation recommendation?
Select an answer first - 44
Why is it important to maintain confidentiality when writing a penetration testing report?
Select an answer first - 45
What is the key characteristic of an effective remediation recommendation in a penetration testing report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.