18B: List Report Contents Flashcards

4.1 Compare and contrast important components of written reports.

1
Q

This is a part of the written report, and is a high level and concise overview of the penetration test, its findings, and their impact. This will typically be geared toward the c-suite.

A

executive summary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A high-level description of the standards or framework followed to conduct the penetration test.

A

methodology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A detailed explanation of the steps taken while performing the activity.

A

attack narrative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A strategic assessment of what level of residual risk is tolerable for an organization.

A

risk appetite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The process of assigning quantitative values to the identified risks.

A

risk rating

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The process of adjusting the final rating of vulnerabilities to the client needs.

A

risk prioritization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Systematic activity that identifies organizational risks and determines their effect on ongoing, mission critical operations.

A

business impact analysis (BIA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Quantifiable measurements of the status of results or processes.

A

metrics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The specific data points that contribute to a metric

A

measures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The possible solution to the issue identified during the penetration test.

A

remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly