CompTIA PenTest+

Reporting & Communication

28 practice questions with explanations — 15 free to try

PassNova has 28 CompTIA PenTest+ practice questions on Reporting & Communication, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Reporting & Communication: example questions & answers

3 worked examples with answers and explanations below. Try 15 CompTIA PenTest+ questions free in the browser; the full 28-question Reporting & Communication bank is part of PassNova Premium.

  1. When prioritising findings in a penetration test report, which scoring system is most commonly used to communicate a standardised severity rating to the client?

    • ACPU benchmark score used to compare processor performance
    • BCVSS (Common Vulnerability Scoring System)
    • CCRC checksum used to detect accidental data corruption
    • DMD5 hash value used to fingerprint a file's contents

    Answer: CVSS provides a standardised numeric severity score for vulnerabilities, giving clients a consistent way to understand and prioritise the risk of each reported finding.

  2. During an engagement a tester discovers an actively exploited critical vulnerability that places the client at immediate risk. According to good practice, what should the tester do?

    • APost the finding on social media for visibility
    • BDelay disclosure of the finding until the final written report has been delivered to the client
    • CImmediately notify the client's designated contact out-of-band before continuing
    • DKeep it secret to avoid alarming the client

    Answer: Critical findings, signs of a prior breach, or imminent risk require immediate out-of-band communication to the client's point of contact rather than holding the information until the formal report, so they can act quickly.

  3. Which section of a penetration test report is written for non-technical leadership and summarises overall risk and business impact in plain language?

    • AThe list of CVE identifiers
    • BThe packet capture logs
    • CThe raw Nmap output appendix
    • DThe executive summary

    Answer: The executive summary distils the engagement's key risks, overall posture, and business impact into concise, non-technical language aimed at senior leadership and decision makers.

Start practising Reporting & Communication →