easyMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration tester is writing the findings…
A penetration tester is writing the findings section of a report. The tester identified a critical SQL injection vulnerability that allows extraction of the entire customer database. The client's technical team has already remediated the issue. How should the tester present this finding to ensure clarity and usefulness?
⚠ Common exam trap
The trap here is that candidates mistakenly think remediated vulnerabilities should be omitted or minimized, but the PT0-002 exam expects full documentation to maintain report integrity and support post-remediation validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the vulnerability in full, including reproduction steps, impact, and evidence, and note the remediation status
Penetration testing standards (e.g., PTES, OWASP) require full documentation of all findings regardless of remediation status. Including reproduction steps, impact analysis, and evidence ensures the report serves as a permanent record for compliance, audit, and future reference. Noting the remediation status provides clear context that the issue has been resolved, which is critical for stakeholders who need to verify the fix.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include the vulnerability with the risk rating, a brief description, and a note that it was remediated during the test
Why it's wrong here
This option is insufficient because a pentest report must function as a complete technical reference, not just a summary of findings. Without full reproduction steps and impact analysis, the client cannot independently verify the vulnerability, assess residual business risk, or reuse the report as evidence in compliance audits. A brief description and remediation note alone omit the concrete evidence that proves the vulnerability existed and how an attacker could have exploited it.
- ✗
Exclude the vulnerability from the report because it has already been fixed
Why it's wrong here
Excluding a remediated vulnerability distorts the security baseline and destroys valuable forensic history. Even if fixed, the finding demonstrates the test's thoroughness and provides evidence that a real attack path existed, which is essential for the client's incident response planning and risk register. Furthermore, regulatory and compliance frameworks often require documentation of all discovered vulnerabilities regardless of when they were remediated, so exclusion can lead to audit nonconformities.
- ✓
Document the vulnerability in full, including reproduction steps, impact, and evidence, and note the remediation status
Why this is correct
This is the correct approach because a penetration testing report should be a durable, evidence-based artifact that fully documents the vulnerability's lifecycle. By including the exact reproduction steps, impact analysis, and supporting evidence (e.g., screenshots, logs), the client gains a clear understanding of the technical issue, and noting remediation status with verification confirms that the risk has been addressed. This completeness supports the client's compliance obligations and future prevention, while also preserving an accurate historical record of the engagement's findings.
- ✗
Reduce the risk rating of the vulnerability because it has been fixed, and include it in an appendix
Why it's wrong here
Reducing the risk rating because the vulnerability was fixed misrepresents the severity that existed at the time of discovery, which is the critical basis for prioritizing remediation and communicating business risk. The inherent risk is a function of exploitability and impact as observed during the test, independent of any subsequent patch or mitigation; changing it retroactively corrupts the data. Placing the finding in an appendix without the original rating and proper context can mislead stakeholders about the actual exposure history and fail to demonstrate the effectiveness of the remediation effort.
Visual reference
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Evidence
Evidence is any data or documentation that proves an event, action, or condition occurred, crucial for verifying compliance, security incidents, or system changes.
About these practice questions
One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.