CISSP - Security Assessment and Testing (12% of the exam) - Section 6.4

Analyse test output and generate reports including remediation, exception handling, and ethical disclosure.

Analyse test output to produce actionable reports covering remediation recommendations, exception handling rationale, and ethical disclosure obligations. Structure findings so that stakeholders can track remediation progress and so that unresolved exceptions are formally accepted with documented risk ownership.

remediationexception handlingethical disclosuretest output analysis

Practice question for this objective

Free sampleSecurity Assessment and Testingmedium

A penetration test report for a regional bank lists 142 findings spanning critical, high, medium, and low severities across customer-facing and internal systems. The CISO must brief the executive risk committee in two days. Which approach should the CISO take FIRST when preparing the remediation roadmap for that briefing?

  • ASort all findings by CVSS score and instruct asset owners to remediate every critical and high in the next sprint cycle.
  • BForward the raw report to each system owner and ask them to self-rank findings on their own assets before the briefing.
  • CMap each finding to the affected business process and asset criticality, then prioritise based on residual risk to the institution rather than raw severity alone. Correct
  • DGroup findings by the technical control family that failed and present the briefing as a control maturity gap analysis only.
Recognise that test output analysis must translate technical findings into business risk before remediation is prioritised for executive decision-makers. Effective analysis of assessment output prioritises remediation by residual risk to the business, which requires mapping each finding to the affected asset, process, threat exposure, and existing compensating controls. Severity scores such as CVSS are an input, not the answer, because they do not account for business context, and executive committees need the risk-translated view to make funding and acceptance decisions.

Why A is wrong: Pure CVSS sorting ignores business context, exploitability in the bank's environment, and existing compensating controls, so it produces a technically defensible but risk-blind queue that the committee cannot reasonably approve.

Why B is wrong: Delegating triage to system owners with no normalised risk framework produces inconsistent rankings, gaps where owners under-rate their own systems, and a roadmap the CISO cannot defend to the committee as a coherent view.

Why C is correct: CISSP-aligned remediation analysis combines technical severity with asset value, threat exposure, and existing controls so the committee approves remediation based on residual business risk, which is the manager-level lens the exam rewards.

Why D is wrong: A control maturity view is useful later for programme planning but it abstracts away the time-sensitive exploitable findings the committee must decide on, so it is a secondary output, not the first remediation step after a penetration test.

See more CISSP practice questions, answers explained.

Exam traps in Security Assessment and Testing

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • It transfers ownership of the residual risk to the assessment team that discovered the finding, so engineering is no longer accountable for the issue.

    Why it is wrong: Tempting because assessors document findings, but exceptions never reassign accountability to the assessor; the business owner accepts the residual risk and remains accountable. Findings ownership stays with the system owner regardless of who tested.

  • Use the scanner's CVSS base score alone to rank every finding, then patch in strict descending order until the maintenance window closes.

    Why it is wrong: Tempting because CVSS base is universally available and easy to sort on, but base scores ignore environmental factors such as exposure, asset criticality, and compensating controls, so they alone produce a misranked plan.

  • Produce a single technical document containing every finding, payload, and exploitation step, on the basis that executives can ignore detail they do not need.

    Why it is wrong: Tempting because one document avoids duplication, but executives need risk framing rather than raw exploit detail, and a single deeply technical artefact buries the business decisions that the risk committee must take.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.