CISSP - Security Assessment and Testing - Section 6.4

Analyse test output and generate reports including remediation, exception handling, and ethical disclosure.

Analyse test output to produce actionable reports covering remediation recommendations, exception handling rationale, and ethical disclosure obligations. Structure findings so that stakeholders can track remediation progress and so that unresolved exceptions are formally accepted with documented risk ownership.

remediationexception handlingethical disclosuretest output analysis

Practice question for this objective

Free sampleSecurity Assessment and Testingmedium

A penetration test report for a regional bank lists 142 findings spanning critical, high, medium, and low severities across customer-facing and internal systems. The CISO must brief the executive risk committee in two days. Which approach should the CISO take FIRST when preparing the remediation roadmap for that briefing?

  • ASort all findings by CVSS score and instruct asset owners to remediate every critical and high in the next sprint cycle.
  • BForward the raw report to each system owner and ask them to self-rank findings on their own assets before the briefing.
  • CMap each finding to the affected business process and asset criticality, then prioritise based on residual risk to the institution rather than raw severity alone. Correct
  • DGroup findings by the technical control family that failed and present the briefing as a control maturity gap analysis only.
Recognise that test output analysis must translate technical findings into business risk before remediation is prioritised for executive decision-makers. Effective analysis of assessment output prioritises remediation by residual risk to the business, which requires mapping each finding to the affected asset, process, threat exposure, and existing compensating controls. Severity scores such as CVSS are an input, not the answer, because they do not account for business context, and executive committees need the risk-translated view to make funding and acceptance decisions.

Why A is wrong: Pure CVSS sorting ignores business context, exploitability in the bank's environment, and existing compensating controls, so it produces a technically defensible but risk-blind queue that the committee cannot reasonably approve.

Why B is wrong: Delegating triage to system owners with no normalised risk framework produces inconsistent rankings, gaps where owners under-rate their own systems, and a roadmap the CISO cannot defend to the committee as a coherent view.

Why C is correct: CISSP-aligned remediation analysis combines technical severity with asset value, threat exposure, and existing controls so the committee approves remediation based on residual business risk, which is the manager-level lens the exam rewards.

Why D is wrong: A control maturity view is useful later for programme planning but it abstracts away the time-sensitive exploitable findings the committee must decide on, so it is a secondary output, not the first remediation step after a penetration test.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security Assessment and Testing objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.