How should penetration testers prioritize findings in a report?
Which of the following describes how a penetration tester could prioritize findings in a report?
Community Votes
50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests risk-based prioritization, where a tester must consider how each vulnerability affects business operations; the common trap is selecting 'cyberthreats' because it sounds security-related, while ignoring asset value and business impact.
In penetration testing, prioritizing report findings is best accomplished by aligning vulnerabilities with the organization's business mission and goals. Although the community vote is split, the correct approach focuses on business risk and critical assets, not threats alone.
The most common wrong answer is D, 'Cyberthreats,' because testers assume findings should be ranked by threat severity or exploitability. However, this ignores the organization's critical operations and asset value, which are key to determining real business risk.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A, 'Business mission and goals,' is the correct answer because penetration test findings should be prioritized based on the potential impact on the organization's critical operations. A vulnerability that affects a revenue-generating application or sensitive data may be more critical than a flaw in a low-value asset, even if the threat severity is similar. CompTIA's PenTest+ framework emphasizes tying remediation priorities to business risk and ensuring the report supports informed decision-making by management.
Community comments [3] and [6] correctly explain this by noting that aligning findings with business goals ensures the greatest risks to critical operations are addressed first. The penetration tester should use the initial scoping discussions to understand what the client considers critical, then rank findings accordingly.
Why the Other Options Are Wrong
Option D, 'Cyberthreats,' is too generic because threats alone do not determine prioritization; a threat must be combined with vulnerability, asset value, and business impact to produce meaningful risk. B, 'Cyberassets,' is incomplete because asset categories such as data or systems are simply objects of risk, not a prioritization method. C, 'Network infrastructure,' is an even narrower subset and would ignore application-level and process-level findings.
Prioritization in a pentest report is a risk-management exercise, and the client's business mission and goals are what give context to the value of each impacted asset. Without that context, the tester might rank a high-severity vulnerability in a non-critical system above a lower-severity issue that directly threatens core operations.
Community Comment Notes
Commenters supporting D, such as [5] and [7], argue that a pentester should not care about business goals, but this contradicts modern pentesting practices where scoping and risk assessment are driven by the client's objectives. Comment [2] correctly notes that not all cyber threats match the business mission, which actually supports A: threat relevance is determined by business context. The stronger reasoning, as seen in [3], [6], and [8], is that business mission and goals must guide prioritization for the report to be actionable.
Ultimately, the suggested answer D likely comes from a surface-level reading of the question, but the deeper exam concept is business impact-driven risk ranking. This is a classic case where 'security' and 'business risk' must be combined.
Official Reference
Exam Strategy
Always approach prioritization questions by thinking about risk = likelihood × impact, and remember that impact is defined by the importance of the asset to the client's business mission. If an answer option mentions aligning findings with business goals or critical operations, choose it over generic technical categories like threats, assets, or infrastructure.