exam questions

Exam PT0-001 All Questions

View all questions & answers for the PT0-001 exam

Exam PT0-001 topic 1 question 188 discussion

Actual exam question from CompTIA's PT0-001
Question #: 188
Topic #: 1
[All PT0-001 Questions]

A penetration tester needs to provide the code used to exploit a DNS server in the final report. In which of the following parts of the report should the penetration tester place the code?

  • A. Executive summary
  • B. Remediation
  • C. Conclusion
  • D. Technical summary
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
smalltech
Highly Voted 3 years, 10 months ago
B. Findings and Remediation Findings are the evidence of impact that were identified during testing. These describe the results of testing. Sometimes, this is separated into a technical report. But findings and remediation describe the results of testing in depth. In general, findings should include at least the following details: • A unique finding label • A rating of relative severity • Evidence to demonstrate the impact/success of exploitation (often screenshots) • Command lines or details to replicate the finding (may include sample scripts) • Affected assets (e.g., where is it found) • Recommendations for remediation or mitigation • A description
upvoted 8 times
...
flash1620
Highly Voted 3 years, 11 months ago
Answer is B. Remediation and Findings section is where you include detailed information and screenshots to include the steps you took to exploit a vulnerability.
upvoted 7 times
joaks
3 years, 10 months ago
Agreed. This is the section for this.
upvoted 1 times
...
x0hmei
3 years, 10 months ago
How's that? Remediation is the steps to fix the findings
upvoted 2 times
boooliyooo
3 years, 10 months ago
it's probabyl because technical summary is still a summary. It's not a place for coding...
upvoted 2 times
casandre123
3 years, 7 months ago
Agree to disagree.. Nowhere in the remediation you should include code, unless the code you are including does precisely that: Remediate. In this case they are asking for the code of the exploit used, the technical summary =! the executive summary which looks to just put everything in a nutshell; The technical summary would be the perfect place to put all you artillery and show everything you did. I know you guys know your sh't but for this one I'll trust my backbone.
upvoted 1 times
...
Yanos_kv
3 years, 10 months ago
does that mean D is the solution?
upvoted 1 times
haly
3 years, 9 months ago
I will will go with D
upvoted 1 times
...
...
...
...
...
kloug
Most Recent 2 years, 2 months ago
dddddddddddd
upvoted 1 times
...
miabe
2 years, 9 months ago
Selected Answer: D
looks good to me
upvoted 1 times
...
cuernov
3 years ago
Selected Answer: D
A. Executive summary -- high level for CEO or non personal people can undestand B. Remediation -- Steps to fix vulnerability C. Conclusion -- Conclusion or all findings D. Technical summary -- Steps to exploit for tecnical people to know how to replicate. I will choose D that the part of the report you put code.
upvoted 2 times
...
baybay
3 years ago
Selected Answer: B
Remediation (& Findings) According to the CompTIA Pentest Study Guide, this section describes the security issues that you discovered during the penetration test and offers suggestions on how the organization might remediate those issue to reduce their level of cybersecurity risk.
upvoted 1 times
...
carlo479
3 years, 9 months ago
B. this was on the exam
upvoted 4 times
casandre123
3 years, 6 months ago
Carlo what are you talking about? If this was on the exam and you chose B, then those were lost points. where in the world would you put the code of your exploit as remediation? Executive summary? No way, executives have no clue. Technical summary? Ding ding ding... Technical; The people reviewing this do know about code and will be able to extract useful info from the code.
upvoted 6 times
...
...
smalltech
3 years, 9 months ago
B.Comptia Pentest has four section in relation to providing report and i have not idea from where you get the technical summary part ? Executive summary Findings and remediations Methodology Conclusion
upvoted 2 times
...
hellobob
3 years, 10 months ago
D seems more appropriate too me.
upvoted 3 times
...
pro100keks
3 years, 10 months ago
What about D? So A is not where you put code. B & C dont really fit.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago