Findings Report | Complete Security Assessment |
Passed Performance Assessment 2026
WGU FailSafe Web Application Penetration Test Findings Report – Practice Exam
SECTION 1: SECURITY TESTING METHODOLOGIES & REPORTING
1. What is the primary purpose of a penetration test findings report?
A) To list all software features
B) To identify and document vulnerabilities and provide remediation
recommendations
C) To calculate project costs
D) To document user requirements
Correct Answer: B) To identify and document vulnerabilities and provide
remediation recommendations
Explanation: A penetration test findings report documents identified security
weaknesses, their risk levels, and provides actionable remediation
recommendations for stakeholders to improve the security posture of the
application .
2. Which of the following should be included in a penetration test findings
summary?
A) The type and number of issues identified
B) Any consistent themes derived from the findings
C) Remediation recommendations
D) All of the above
,Correct Answer: D) All of the above
Explanation: A findings summary should be prepared for each type of security
testing, providing the type and number of issues identified and any consistent
theme that can be derived from the findings .
3. What is the OWASP risk rating methodology used for in a penetration test
report?
A) To determine the project budget
B) To evaluate the likelihood and impact of each vulnerability
C) To select testing tools
D) To assign testers to specific tasks
Correct Answer: B) To evaluate the likelihood and impact of each vulnerability
Explanation: The OWASP risk rating methodology evaluates both the likelihood
(threat agent and vulnerability factors) and the impact (technical and business
consequences) of each vulnerability to prioritize remediation efforts .
4. The OWASP risk rating methodology rates impact based on which two
categories?
A) Technical impact and business impact
B) Cost impact and schedule impact
C) User impact and developer impact
D) Short-term impact and long-term impact
Correct Answer: A) Technical impact and business impact
Explanation: Impact is rated based on the technical impact (loss of confidentiality,
integrity, availability, and accountability) and business impact (financial damage,
reputational damage, non-compliance, and privacy violations) .
, 5. How does the sensitivity of information on a site affect the severity of a
vulnerability?
A) It has no effect on severity
B) The same vulnerability is more severe on a site with sensitive information
C) Sensitivity only affects compliance requirements
D) Sensitivity only affects reporting format
Correct Answer: B) The same vulnerability is more severe on a site with sensitive
information
Explanation: There is a huge difference in the type and the sensitivity of the
information present on each site. A vulnerability found in a site with sensitive data
is a lot more severe than the same vulnerability found in a site with less sensitive
information .
6. What factors affect the likelihood of an exploit being successful?
A) The technical skills of the threat agent
B) The trade-off between the reward and how easy the exploit is to achieve
C) The technical skills of the threat agent and the reward vs. effort trade-off
D) Only the technical skills of the threat agent
Correct Answer: C) The technical skills of the threat agent and the reward vs.
effort trade-off
Explanation: The likelihood of an exploit is affected by the technical skills of the
threat agent and the trade-off between the reward and how easy the exploit is to
achieve. If the reward is high, an attacker might invest a lot in gaining it .
7. Which of the following is NOT typically included in a security testing report?
A) Type of issues identified
B) Number of issues identified