CompTIA PenTest+ (PT0-003)Engagement ManagementHard
After a client's IT team applies patches for all critical findings from a penetration test report, they ask the testing firm to confirm the vulnerabilities have actually been fixed before closing out the engagement. What should the testing firm perform to satisfy this request?
- AAn updated SOW covering a brand-new assessment
- BA retest/attestation of the previously identified findings
- CA repeat of the OSSTMM RAV calculation from scratch
- DA fresh full-scope nmap discovery scan of the entire network
Show answer & explanationAnswer & explanation
Correct answer: B. A retest/attestation of the previously identified findings
A retest, also called attestation of findings, focuses specifically on re-validating the previously reported vulnerabilities to confirm remediation was effective, rather than performing a brand-new broad assessment. This provides the client with formal confirmation that the fixes worked.
Why the other options are wrong
- A. A new SOW for a fresh assessment is unnecessary when only confirming existing remediation is required.
- C. Recalculating RAV scores measures overall security posture, not confirmation of specific patch effectiveness.
- D. A full discovery scan of the whole network goes beyond what's needed to confirm specific fixes.
Retest / Attestation of Findings
A follow-up validation activity where the tester re-examines previously reported vulnerabilities to confirm that remediation efforts were effective.
- Focused only on previously identified findings, not a full new assessment
- Often documented in a short attestation letter or addendum report
- May be included in the original SOW or billed as an additional engagement
Memory trick: Deliver, Destroy, reDo (retest), Done: the four D's after the report.