Q: 9
[Reporting and Communication]
Which of the following elements of a penetration test report can be used to most effectively
prioritize the remediation efforts for all the findings?
Options
Discussion
Option C solid question clarity here. Risk score lets you tackle what matters first.
Isn't B just a list without priority? Wouldn't the risk score be more actionable for remediation?
Its C, had something like this in a mock, risk score lets you prioritize easily.
C makes sense but I've seen some reports that push the detailed findings list (B) for remediation order. Still, risk score lines up more with how most teams triage in practice. Anyone see a report where B is preferred?
Be respectful. No spam.