Courseiva
hardMultiple Choice

Best Way to Report a Vulnerability So the Client Can Reproduce and Fix It

Exhibit

Refer to the exhibit.

Exhibit: Web application vulnerability scanner output
```
Vulnerability: SQL Injection
URL: https://example.com/search?q=test
Parameter: q
Payload: ' OR 1=1--
Evidence: Error message shows database version: Microsoft SQL Server 2016 (RTM)
Severity: Critical
```

Refer to the exhibit. A penetration tester used a vulnerability scanner and obtained the above result. What is the BEST way to represent this finding in the report to ensure the client can reproduce and fix it?

Quick Answer

The correct answer is to include the full request with the exact payload and evidence. This is the best way to represent a finding for reproduction because a client’s development team needs the complete HTTP request, including headers, parameters, and the specific injection payload, to replicate the vulnerability in their own environment. Without the full request, they cannot verify the exact conditions that triggered the flaw, making remediation guesswork. On the CompTIA PenTest+ PT0-002 exam, this question tests your understanding of reporting standards under Objective 4.2, where the common trap is thinking a URL or error message alone suffices. The key is that evidence must be actionable—scanner names or partial details are irrelevant. Remember the mnemonic “FREP” for Full Request, Exact Payload, and Proof—if you can’t copy-paste it into a browser or tool to reproduce the issue, your report is incomplete.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Include the full request with the exact payload and evidence.

Including the full HTTP request with the exact payload and supporting evidence gives the client everything needed to reproduce the finding and verify a fix, which is the standard for a professional penetration test report. The full request preserves the method, endpoint, headers, cookies, and parameter values, while the payload and evidence demonstrate the actual exploitability rather than just asserting it. Option A is insufficient because a URL and parameter name alone omit the request method, headers, and payload needed to trigger the issue. Option C is too narrow, since a database error message is only one possible piece of evidence and may not be present or may not show how to reproduce the flaw. Option D is irrelevant to reproduction, as naming the scanner and version does not provide the request details or proof required to confirm and remediate the vulnerability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Include only the URL and parameter name.

    Why it's wrong here

    The URL and parameter name alone omit the payload, request method and response evidence, so the client cannot reproduce or verify the finding. It is tempting because it is concise, but a complete finding requires reproduction steps, evidence and remediation guidance.

  • ✓

    Include the full request with the exact payload and evidence.

    Why this is correct

    Reproducibility requires the exact HTTP request, including headers, parameters and payload, plus the observed response as evidence. This lets the client replay the request against their own system and confirm the vulnerability before remediating it.

  • ✗

    Provide the exact error message from the database.

    Why it's wrong here

    A raw database error message alone omits the request, endpoint and payload needed to reproduce the issue, and may expose sensitive data. It is tempting because error text can hint at the underlying flaw, but the report needs the full reproduction steps and evidence.

  • ✗

    List the vulnerability scanner used and its version.

    Why it's wrong here

    Naming the scanner and version documents tooling, not the finding, so the client cannot reproduce or remediate the issue. It is tempting because scanner provenance supports report credibility and audit trails, but reproduction requires the request, payload and response evidence instead.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on PT0-003

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Refer to the exhibit. A penetration tester performed an initial nmap scan and recorded the above output. The tester wants to include this in the report. What additional information should the tester add to make the finding more useful for remediation?

medium
  • ✓ A.The version of services running on each port.
  • B.The list of open ports only.
  • C.The operating system of each host.
  • D.The result of a UDP scan for these ports.

Why A: The correct option is A, the version of services running on each port, because knowing the exact service and version (e.g., Apache 2.4.49, OpenSSH 8.2p1) lets defenders map findings to known CVEs and apply targeted patches or upgrades. A raw nmap port list only shows TCP/UDP openness and cannot drive remediation without identifying the vulnerable software behind each port. Option B is insufficient because open ports alone do not reveal exploitable services. Option C, the OS of each host, is useful context but does not identify the vulnerable application layer. Option D, a UDP scan, expands coverage but still does not provide the service-version detail needed for remediation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.