Which Post-Report Activity Prevents CISO Disputing Finding Validity?
An organization’s Chief Information Security Officer debates the validity of a critical finding from a penetration assessment that was completed six months ago. Which of the following post-report delivery activities would have most likely prevented this scenario?
Community Votes
47% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to distinguish client acceptance (the client agrees with findings) from attestation (the tester formally declares findings accurate), and the trap is confusing who is doing the validating.
Learn which post-report delivery activity in CompTIA Pentest+ PT0-002 prevents clients from later disputing finding validity. Community votes favor Client Acceptance over Attestation of Findings, with the distinction centered on who formally validates the report.
Choosing Attestation of Findings is the most common wrong answer because it sounds like confirming validity, but attestation is the tester's declaration, not the client's acceptance of the report.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Client acceptance is the formal close-out step where the client reviews the report and agrees that the testing is complete and the findings are valid. As one community comment quoting the PT0-002 Study Guide notes, the formal hand-off includes getting confirmation that the client accepts the findings as presented. If the CISO had accepted the findings during that process, debating their validity six months later would be unlikely. The key is that client acceptance is the client's own confirmation, not the tester's.Why the Other Options Are Wrong
Attestation of findings (C) is a popular distractor; commenters correctly point out that attestation is the penetration tester attesting to the accuracy of the report, not the client's sign-off. Data destruction (B) concerns securely disposing of test data and is unrelated to finding validity. Lessons learned (D) is a process improvement review, not a formal validation of findings. Users who argue for C are confusing the subject of the attestation with the client acceptance step.Community Comment Notes
The comment section is split, with many users voting C because they interpret attestation as client acknowledgment (comments 1 and 2). However, higher-voted answers and the official study guide reference (comment 3) clarify that client acceptance is the correct post-delivery sign-off. Comment 4 incorrectly conflates attestation with client acceptance, showing how easily these terms are mixed up. The suggested answer A aligns with the CompTIA definition of client acceptance as the client's agreement with the findings.Official Reference
Exam Strategy
Remember the party performing the action: 'client acceptance' is done by the client, while 'attestation' is done by the tester. On the exam, look for wording indicating who is validating the report—if the customer challenges a finding, client acceptance is the post-report activity that locks in their agreement.