What Is the Next Step After Initial Findings Review in a Pentest Engagement?

Penetration-testing activities have concluded, and the initial findings have been reviewed with the client. Which of the following best describes the NEXT step in the engagement?

  1. Performing a live demonstration of the results to the system administrators
  2. Scheduling of follow-up actions and retesting
  3. Attestation of findings and delivery of the report Source Reference Answer
  4. Review of the lessons during the engagement

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the standard penetration testing engagement workflow, particularly the reporting phase. The trap is confusing post-report activities (like retesting) with the immediate next step, which is report attestation and delivery.

After penetration testing activities conclude and initial findings are reviewed, the next step is attesting findings and delivering the final report. The CompTIA community agrees that report delivery precedes follow-up actions like retesting and lessons learned.

A common wrong answer is B (scheduling follow-up actions and retesting) because it seems logical, but the report must be delivered first to formalize findings and recommendations. Another common mistake is D (lessons learned), which occurs after report delivery.

Community Discussion (3 comments)

PhillyCheese 👍 1 Selected: C
The next step in the engagement after reviewing initial findings with the client is to attest the findings and deliver the report. This report provides a detailed account of vulnerabilities, risks, and recommended actions. It serves as a crucial communication tool for stakeholders and guides subsequent actions. While live demonstrations and lessons learned are valuable, they typically occur later in the process.
041ba31 👍 1 Selected: C
After initial review of findings with the client, the next step is attesting the findings and delivering the final report, detailing vulnerabilities, impacts, and recommendations
Big_Dre 👍 1 Selected: C
C. Attestation of findings and delivery of the report After the penetration-testing activities have concluded and the initial findings have been reviewed with the client, the next step in the engagement typically involves attesting to the findings and delivering the final report to the client. This report will detail all the vulnerabilities discovered, the potential impacts of these vulnerabilities, and recommendations for remediation. This step is crucial for providing the client with a comprehensive understanding of the security posture of their systems and the necessary steps to improve it.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

After initial findings have been reviewed with the client, the engagement officially moves to the reporting phase. CompTIA's penetration testing process requires the pentester to attest to the findings (i.e., validate and confirm) and deliver the final report to the client. This report is the formal deliverable that documents vulnerabilities, risk ratings, and remediation guidance. Only after the report is delivered can subsequent actions like retesting or lessons learned be scheduled. The commenter [1] correctly notes that the report serves as the primary communication tool for stakeholders.

Why the Other Options Are Wrong

A (live demonstration) is a supplementary activity that may occur after report delivery, but it is not the immediate next step. B (retesting) occurs after the client has had time to remediate issues, which is a later phase. D (lessons learned) is typically part of a post-engagement review, also after the report is finalized. The question asks for the 'next step' after the initial review, so the logical sequence is to finalize and deliver the report.

Community Comment Notes

All three comments support answer C. Comment [2] explicitly states, 'the next step is attesting the findings and delivering the final report.' Comment [3] elaborates that the report details vulnerabilities and impacts. Comment [1] notes that live demonstrations and lessons learned 'typically occur later.' The unanimous consensus reinforces that the correct sequence is report delivery first.

Official Reference

Exam Strategy

When asked about the next step in a pentest engagement, remember the deliverable timeline: report delivery comes first. After the initial findings review, the immediate requirement is to formalize and deliver the report, not to schedule retests or lessons learned.

Related Analysis

← Back to PT0-002 Study Guide