312-50 exam dumps

312-50 practice question 125 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 125

Single answer▪ Vulnerability Assessment Reports

A security consultant delivers a vulnerability assessment report for a public-facing web application. The report lists 140 findings from an automated scanner, including several informational items, multiple medium-severity issues, and one critical finding: a confirmed SQL injection on the login form that exposes customer records. The client’s IT manager says the report is too long and asks for a concise executive summary that helps leadership decide what to fix first. Which action should the consultant take FIRST to make the report most useful for remediation planning and executive decision-making?

  1. A

    Reorganize the report by business risk, highlighting the confirmed SQL injection, affected assets, potential impact, and prioritized remediation recommendations

  2. B

    Remove all informational and medium findings so leadership focuses only on the single critical issue

  3. C

    Sort findings alphabetically by vulnerability name so the report is easier to read

  4. D

    Replace technical details with CVSS scores only, since executives do not need remediation context

Show answer and explanation

Correct answer: A

Explanation

In CEH-aligned practice, a vulnerability assessment report should do more than dump scanner results; it should translate findings into prioritized, actionable risk information. Best practice is to tailor reporting for different audiences: an executive summary for leadership and a technical section for remediation teams. Risk-based prioritization should consider severity, exploitability, exposure, asset criticality, and business impact. A confirmed SQL injection affecting customer data on a public-facing login form is a high-priority finding because it represents direct compromise risk and potential regulatory and reputational impact. Industry guidance from sources such as NIST's vulnerability management recommendations and the Common Vulnerability Scoring System (CVSS) supports using severity as one input, but not the only one; effective remediation planning also depends on asset value and real-world context.

  • A. Correct.

    Correct. A strong vulnerability assessment report should be actionable and audience-appropriate. For executive and remediation planning purposes, findings should be prioritized by risk to the organization, not just listed as raw scanner output. Highlighting the confirmed SQL injection, affected systems, business impact, likelihood, and remediation steps helps both leadership and technical teams make informed decisions quickly.

  • B. Incorrect.

    Incorrect. Removing all informational and medium findings is not a sound reporting practice. While executive summaries should emphasize the highest-risk issues, the full report should still preserve lower-severity items for remediation tracking, trend analysis, and defense-in-depth improvements. Medium findings can still be important, especially when combined or when they affect exposed systems.

  • C. Incorrect.

    Incorrect. Alphabetical sorting may improve readability slightly, but it does not support risk-based decision-making. Vulnerability assessment reports are most useful when they help stakeholders understand priority, impact, and remediation order rather than presenting findings in an arbitrary organizational format.

  • D. Incorrect.

    Incorrect. CVSS scores are useful for standardizing severity, but they are not sufficient by themselves. Effective reports also include asset context, exploitability, business impact, evidence, and recommended fixes. Executives often need concise business-oriented context, and technical teams need enough detail to validate and remediate the issue properly.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam