How should penetration testers prioritize findings in a report?

Which of the following describes how a penetration tester could prioritize findings in a report?

  1. Business mission and goats
  2. Cyberassets
  3. Network infrastructure
  4. Cyberthreats Source Reference Answer

Community Votes

D
50%
A
50%

50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests risk-based prioritization, where a tester must consider how each vulnerability affects business operations; the common trap is selecting 'cyberthreats' because it sounds security-related, while ignoring asset value and business impact.

In penetration testing, prioritizing report findings is best accomplished by aligning vulnerabilities with the organization's business mission and goals. Although the community vote is split, the correct approach focuses on business risk and critical assets, not threats alone.

The most common wrong answer is D, 'Cyberthreats,' because testers assume findings should be ranked by threat severity or exploitability. However, this ignores the organization's critical operations and asset value, which are key to determining real business risk.

Community Discussion (10 comments)

study_study 👍 1 Selected: D
I am going D. A pentester doesn't care what the businesses goals are and that doesn't affect the criticality of the vulnerabilities.
kinny4000 👍 1 Selected: A
Gotta prioritise vulnerabilities based on the companies goals (i.e. making money - critical devices like webservers that host shops or databases with customer info / inventing things - research data must be protected above webservers). This would be discussed during the initial meeting, defining what is 'critical' or 'severe' depends on the business missions and goats.
hitagitore 👍 1 Selected: D
you have to remember you are not the CEO of the company but the security tester. it doesn't make sense for a tester (not to mention a 3rd party tester) to consider business goals.
Vslaugh 👍 1 Selected: A
You would prioritize findings based on how the vulnerabilities impact that client's business mission and goals, so I'm going with A
Alex818119 👍 1 Selected: D
Seems to make more sense
PTA 👍 2 Selected: D
makes better sense
fecffa8 👍 2 Selected: A
Aligning security findings with the organization's business mission and goals ensures that vulnerabilities posing the greatest risk to critical operations are addressed first. This approach considers the potential impact of each vulnerability on the organization's objectives, enabling informed decision-making.
mamoru 👍 3 Selected: A
I'm vote for A. not all cyber threats are match with business mission
b1484e5 👍 2 Selected: A
I would think business missions and goals would influence prioritization
Ta2oo 👍 4 Selected: D
Penetration testing is all about identifying vulnerabilities. So D, prioritising by cyber threats makes sense to me.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A, 'Business mission and goals,' is the correct answer because penetration test findings should be prioritized based on the potential impact on the organization's critical operations. A vulnerability that affects a revenue-generating application or sensitive data may be more critical than a flaw in a low-value asset, even if the threat severity is similar. CompTIA's PenTest+ framework emphasizes tying remediation priorities to business risk and ensuring the report supports informed decision-making by management.

Community comments [3] and [6] correctly explain this by noting that aligning findings with business goals ensures the greatest risks to critical operations are addressed first. The penetration tester should use the initial scoping discussions to understand what the client considers critical, then rank findings accordingly.

Why the Other Options Are Wrong

Option D, 'Cyberthreats,' is too generic because threats alone do not determine prioritization; a threat must be combined with vulnerability, asset value, and business impact to produce meaningful risk. B, 'Cyberassets,' is incomplete because asset categories such as data or systems are simply objects of risk, not a prioritization method. C, 'Network infrastructure,' is an even narrower subset and would ignore application-level and process-level findings.

Prioritization in a pentest report is a risk-management exercise, and the client's business mission and goals are what give context to the value of each impacted asset. Without that context, the tester might rank a high-severity vulnerability in a non-critical system above a lower-severity issue that directly threatens core operations.

Community Comment Notes

Commenters supporting D, such as [5] and [7], argue that a pentester should not care about business goals, but this contradicts modern pentesting practices where scoping and risk assessment are driven by the client's objectives. Comment [2] correctly notes that not all cyber threats match the business mission, which actually supports A: threat relevance is determined by business context. The stronger reasoning, as seen in [3], [6], and [8], is that business mission and goals must guide prioritization for the report to be actionable.

Ultimately, the suggested answer D likely comes from a surface-level reading of the question, but the deeper exam concept is business impact-driven risk ranking. This is a classic case where 'security' and 'business risk' must be combined.

Official Reference

Exam Strategy

Always approach prioritization questions by thinking about risk = likelihood × impact, and remember that impact is defined by the importance of the asset to the client's business mission. If an answer option mentions aligning findings with business goals or critical operations, choose it over generic technical categories like threats, assets, or infrastructure.

Related Analysis

← Back to PT0-002 Study Guide