• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 21 pages
Exam (elaborations)

WGU FailSafe Web Application Penetration Test Findings Report Questions and Correct Answers.pdf

Document preview thumbnail
Preview 3 out of 21 pages

WGU FailSafe Web Application Penetration Test Findings Report Questions and Correct A WGU FailSafe Web Application Penetration Test Findings Report Questions and Correct A WGU FailSafe Web Application Penetration Test Findings Report Questions and Correct A

Content preview

WGU FailSafe Web Application Penetration Test
Findings Report | Complete Security Assessment |
Passed Performance Assessment 2026

WGU FailSafe Web Application Penetration Test Findings Report – Practice Exam


SECTION 1: SECURITY TESTING METHODOLOGIES & REPORTING
1. What is the primary purpose of a penetration test findings report?
A) To list all software features
B) To identify and document vulnerabilities and provide remediation
recommendations
C) To calculate project costs
D) To document user requirements
Correct Answer: B) To identify and document vulnerabilities and provide
remediation recommendations
Explanation: A penetration test findings report documents identified security
weaknesses, their risk levels, and provides actionable remediation
recommendations for stakeholders to improve the security posture of the
application .


2. Which of the following should be included in a penetration test findings
summary?
A) The type and number of issues identified
B) Any consistent themes derived from the findings
C) Remediation recommendations
D) All of the above

,Correct Answer: D) All of the above
Explanation: A findings summary should be prepared for each type of security
testing, providing the type and number of issues identified and any consistent
theme that can be derived from the findings .


3. What is the OWASP risk rating methodology used for in a penetration test
report?
A) To determine the project budget
B) To evaluate the likelihood and impact of each vulnerability
C) To select testing tools
D) To assign testers to specific tasks
Correct Answer: B) To evaluate the likelihood and impact of each vulnerability
Explanation: The OWASP risk rating methodology evaluates both the likelihood
(threat agent and vulnerability factors) and the impact (technical and business
consequences) of each vulnerability to prioritize remediation efforts .


4. The OWASP risk rating methodology rates impact based on which two
categories?
A) Technical impact and business impact
B) Cost impact and schedule impact
C) User impact and developer impact
D) Short-term impact and long-term impact
Correct Answer: A) Technical impact and business impact
Explanation: Impact is rated based on the technical impact (loss of confidentiality,
integrity, availability, and accountability) and business impact (financial damage,
reputational damage, non-compliance, and privacy violations) .

, 5. How does the sensitivity of information on a site affect the severity of a
vulnerability?
A) It has no effect on severity
B) The same vulnerability is more severe on a site with sensitive information
C) Sensitivity only affects compliance requirements
D) Sensitivity only affects reporting format
Correct Answer: B) The same vulnerability is more severe on a site with sensitive
information
Explanation: There is a huge difference in the type and the sensitivity of the
information present on each site. A vulnerability found in a site with sensitive data
is a lot more severe than the same vulnerability found in a site with less sensitive
information .


6. What factors affect the likelihood of an exploit being successful?
A) The technical skills of the threat agent
B) The trade-off between the reward and how easy the exploit is to achieve
C) The technical skills of the threat agent and the reward vs. effort trade-off
D) Only the technical skills of the threat agent
Correct Answer: C) The technical skills of the threat agent and the reward vs.
effort trade-off
Explanation: The likelihood of an exploit is affected by the technical skills of the
threat agent and the trade-off between the reward and how easy the exploit is to
achieve. If the reward is high, an attacker might invest a lot in gaining it .


7. Which of the following is NOT typically included in a security testing report?
A) Type of issues identified
B) Number of issues identified

Document information

Uploaded on
July 9, 2026
Number of pages
21
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$21.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
442
Last sold
-



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions