Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 7Objective 4

Report Writing and Post-Testing Actions CPENT Practice Questions (Page 9)

Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.

52questions here
11free pages
10concepts

Questions 41–45

  1. 41expert · hard

    After completing a penetration test, you discover that a tester left an SSH key on a compromised server that was used for persistence. The tester is on vacation and cannot be reached. The client's server is critical to production and cannot be taken offline. What is the most appropriate cleanup action?

    Select an answer first
  2. 42expert · hard

    You are preparing a penetration test report for a client that will be audited by an external regulator. The regulator requires that the report clearly show the testing scope, methodology, and evidence for each finding. The client also wants the report to be concise for internal distribution. How should you format the report?

    Select an answer first
  3. 43application · medium

    Your penetration test identified a critical SQL injection vulnerability in a customer-facing application and a low-severity information disclosure in an internal tool. The client has limited development resources this quarter. What is the most appropriate remediation recommendation?

    Select an answer first
  4. 44foundation · easy

    Why is it important to maintain confidentiality when writing a penetration testing report?

    Select an answer first
  5. 45foundation · easy

    What is the key characteristic of an effective remediation recommendation in a penetration testing report?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.