A penetration tester is preparing a post-engagement deliverable. Which THREE of the following should be included in the final report? (Select THREE.)
Trap 1: Detailed log of every command executed
A detailed log of every command executed is unsuitable for a final client deliverable because it exposes internal tooling, attack paths, and potentially sensitive data that the client does not need for remediation. It also contains extensive operational noise—such as false starts, recon pings, and test modifications—that obscures the actual security findings. Such logs belong in the tester's working notes or an appendix for audit purposes, not in the executive- or technical-facing report, as they provide little actionable value to the client's security team.
Trap 2: Tester's hourly billing breakdown
An hourly billing breakdown is a contractual and administrative document, not part of the technical penetration test report. It contains sensitive financial information that is irrelevant to the security findings and could distract from the technical and business messages the report is meant to convey. Billing details are typically handled by the consulting firm's accounting department and delivered separately, ensuring the report remains focused on security outcomes rather than vendor commercial arrangements.
- A
Remediation guidance
Remediation guidance is essential because it transforms raw vulnerability data into actionable, prioritized steps the client can implement to reduce risk. It should map each finding to a specific fix, reference standards such as CWE or NIST, and include validation techniques to confirm the remediation was effective. This section directly fulfills the client's goal of improving security posture, making it a core component of any professional penetration test report.
- B
Detailed log of every command executed
Why it fails: A detailed log of every command executed is unsuitable for a final client deliverable because it exposes internal tooling, attack paths, and potentially sensitive data that the client does not need for remediation. It also contains extensive operational noise—such as false starts, recon pings, and test modifications—that obscures the actual security findings. Such logs belong in the tester's working notes or an appendix for audit purposes, not in the executive- or technical-facing report, as they provide little actionable value to the client's security team.
- C
Executive summary
An executive summary bridges the gap between the technical findings and the business stakeholders who fund and approve security initiatives. It must clearly convey the overall risk posture, the number and severity of vulnerabilities, and the potential business impact without requiring deep technical knowledge. This section often drives the decision-making process for allocating resources to remediation, so it must be concise, visually digestible, and aligned with the organization's risk tolerance.
- D
Technical findings and vulnerabilities
Technical findings and vulnerabilities form the core body of the report, providing a detailed, evidence-based account of each security issue discovered during the assessment. Each finding should include the affected asset, the vulnerability identifier (e.g., CVE ID), a CVSS score, step-by-step reproduction instructions, and proof-of-concept screenshots or output. This level of detail enables the client's technical staff to independently verify the issue, prioritize fixes based on real environmental context, and track remediation progress over time.
- E
Tester's hourly billing breakdown
Why it fails: An hourly billing breakdown is a contractual and administrative document, not part of the technical penetration test report. It contains sensitive financial information that is irrelevant to the security findings and could distract from the technical and business messages the report is meant to convey. Billing details are typically handled by the consulting firm's accounting department and delivered separately, ensuring the report remains focused on security outcomes rather than vendor commercial arrangements.