The best time to issue a status report is at predetermined intervals specified in the rules of engagement or the contract. This ensures that the client is regularly updated and can make decisions based on the latest findings. Providing reports only when high-severity vulnerabilities are discovered might leave the client uninformed about the overall progress of the test. Reporting after each vulnerability may overwhelm the client with information and may not be practical. Waiting until after the test to report on issues excludes the possibility for the client to make essential decisions during the test.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are rules of engagement in a penetration test?
Open an interactive chat with Bash
Why is regular reporting important during a penetration test?
Open an interactive chat with Bash
What types of vulnerabilities should be reported during a penetration test?