Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration tester is writing the findings…

A penetration tester is writing the findings section of a report. The tester identified a critical SQL injection vulnerability that allows extraction of the entire customer database. The client's technical team has already remediated the issue. How should the tester present this finding to ensure clarity and usefulness?

⚠ Common exam trap

The trap here is that candidates mistakenly think remediated vulnerabilities should be omitted or minimized, but the PT0-002 exam expects full documentation to maintain report integrity and support post-remediation validation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Document the vulnerability in full, including reproduction steps, impact, and evidence, and note the remediation status

Penetration testing standards (e.g., PTES, OWASP) require full documentation of all findings regardless of remediation status. Including reproduction steps, impact analysis, and evidence ensures the report serves as a permanent record for compliance, audit, and future reference. Noting the remediation status provides clear context that the issue has been resolved, which is critical for stakeholders who need to verify the fix.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Include the vulnerability with the risk rating, a brief description, and a note that it was remediated during the test

    Why it's wrong here

    This option is insufficient because a pentest report must function as a complete technical reference, not just a summary of findings. Without full reproduction steps and impact analysis, the client cannot independently verify the vulnerability, assess residual business risk, or reuse the report as evidence in compliance audits. A brief description and remediation note alone omit the concrete evidence that proves the vulnerability existed and how an attacker could have exploited it.

  • Exclude the vulnerability from the report because it has already been fixed

    Why it's wrong here

    Excluding a remediated vulnerability distorts the security baseline and destroys valuable forensic history. Even if fixed, the finding demonstrates the test's thoroughness and provides evidence that a real attack path existed, which is essential for the client's incident response planning and risk register. Furthermore, regulatory and compliance frameworks often require documentation of all discovered vulnerabilities regardless of when they were remediated, so exclusion can lead to audit nonconformities.

  • Document the vulnerability in full, including reproduction steps, impact, and evidence, and note the remediation status

    Why this is correct

    This is the correct approach because a penetration testing report should be a durable, evidence-based artifact that fully documents the vulnerability's lifecycle. By including the exact reproduction steps, impact analysis, and supporting evidence (e.g., screenshots, logs), the client gains a clear understanding of the technical issue, and noting remediation status with verification confirms that the risk has been addressed. This completeness supports the client's compliance obligations and future prevention, while also preserving an accurate historical record of the engagement's findings.

  • Reduce the risk rating of the vulnerability because it has been fixed, and include it in an appendix

    Why it's wrong here

    Reducing the risk rating because the vulnerability was fixed misrepresents the severity that existed at the time of discovery, which is the critical basis for prioritizing remediation and communicating business risk. The inherent risk is a function of exploitability and impact as observed during the test, independent of any subsequent patch or mitigation; changing it retroactively corrupts the data. Placing the finding in an appendix without the original rating and proper context can mislead stakeholders about the actual exposure history and fail to demonstrate the effectiveness of the remediation effort.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.