Which Post-Report Activity Prevents CISO Disputing Finding Validity?

An organization’s Chief Information Security Officer debates the validity of a critical finding from a penetration assessment that was completed six months ago. Which of the following post-report delivery activities would have most likely prevented this scenario?

  1. Client acceptance Source Reference Answer
  2. Data destruction process
  3. Attestation of findings
  4. Lessons learned

Community Votes

A
47%
C
37%
B
16%

47% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to distinguish client acceptance (the client agrees with findings) from attestation (the tester formally declares findings accurate), and the trap is confusing who is doing the validating.

Learn which post-report delivery activity in CompTIA Pentest+ PT0-002 prevents clients from later disputing finding validity. Community votes favor Client Acceptance over Attestation of Findings, with the distinction centered on who formally validates the report.

Choosing Attestation of Findings is the most common wrong answer because it sounds like confirming validity, but attestation is the tester's declaration, not the client's acceptance of the report.

Community Discussion (8 comments)

Ta2oo 👍 7 Selected: C
C is the correct answer. Attestation before Client acceptance.
mat22 👍 6
Correct answer is C. Attestation of findings is a process in which the client confirms and acknowledges the findings and recommendations presented in a penetration testing report
kinny4000 👍 2 Selected: A
Client acceptance is the process where the client reviews, confirms, and agrees with the findings in the penetration test report. This process ensures that both parties acknowledge the validity of the findings at the time of the report's delivery. If this had been done properly, the CISO would not be debating the validity of the findings six months later.
HiggsBoson_Level 👍 3 Selected: A
Answer is A. From the Pentest+ (PT0-002) Study Guide: Gaining The Client's Acceptance After finishing your PenTest and writing the report, you should plan to have a discussion with the client about the findings in the report. During the formal hand-off process, you will need to get confirmation from the client that they agree that the testing is complete and that they accept your findings as presented in your report.
Fart2023 👍 1 Selected: A
A = Job done everyone happy, C is I just got the report and I have questions. C can't happen 6 months after....
fecffa8 👍 3 Selected: B
Correction. The answer is B. Also from the cert master. Yes client acceptance is them agreeing with you. Attestation is the process of providing evidence that the findings detailed in the PenTest report are true. In other words, by signing off on the report given to the client, you are attesting that you believe the information and conclusions in the report are authentic. Attestation is perhaps the most significant component of gaining client acceptance, as the client must believe that what you have said about their people, processes, and technology is accurate. Many organizations will not simply trust your word that a particular vulnerability exists, even if you've built yourself a good reputation over the years. You must be prepared to prove what you claim. Proof can come in many forms, and those forms usually depend on the nature of what is being proven. For example, if you want to prove that you were able to break into a server holding sensitive data, you could present exfiltrated data to the client as proof.
fecffa8 👍 1 Selected: A
straight from the cert master Gaining The Client's Acceptance After finishing your PenTest and writing the report, you should plan to have a discussion with the client about the findings in the report. During the formal hand-off process, you will need to get confirmation from the client that they agree that the testing is complete and that they accept your findings as presented in your report. Use the meeting to discuss with the client anything that needs to be clarified or changed in the report before they can be confident in its conclusions. Gaining the client's acceptance is of paramount importance, as they will not automatically be satisfied with your report just because you have written one. They need to be convinced that the test was worthwhile from a business standpoint and that it truly met the objectives that were set out during the planning phase.
ZoeAnneTaylor 👍 2 Selected: A
Attestation is only for compliance/regulatory scans. Client acceptance is ... exactly what it sounds like - the client accepting the results. The client in the question did not accept the results of the engagement.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Client acceptance is the formal close-out step where the client reviews the report and agrees that the testing is complete and the findings are valid. As one community comment quoting the PT0-002 Study Guide notes, the formal hand-off includes getting confirmation that the client accepts the findings as presented. If the CISO had accepted the findings during that process, debating their validity six months later would be unlikely. The key is that client acceptance is the client's own confirmation, not the tester's.

Why the Other Options Are Wrong

Attestation of findings (C) is a popular distractor; commenters correctly point out that attestation is the penetration tester attesting to the accuracy of the report, not the client's sign-off. Data destruction (B) concerns securely disposing of test data and is unrelated to finding validity. Lessons learned (D) is a process improvement review, not a formal validation of findings. Users who argue for C are confusing the subject of the attestation with the client acceptance step.

Community Comment Notes

The comment section is split, with many users voting C because they interpret attestation as client acknowledgment (comments 1 and 2). However, higher-voted answers and the official study guide reference (comment 3) clarify that client acceptance is the correct post-delivery sign-off. Comment 4 incorrectly conflates attestation with client acceptance, showing how easily these terms are mixed up. The suggested answer A aligns with the CompTIA definition of client acceptance as the client's agreement with the findings.

Official Reference

Exam Strategy

Remember the party performing the action: 'client acceptance' is done by the client, while 'attestation' is done by the tester. On the exam, look for wording indicating who is validating the report—if the customer challenges a finding, client acceptance is the post-report activity that locks in their agreement.

Related Analysis

← Back to PT0-002 Study Guide