Skip to content

Lab 06 Full Penetration Test and Professional Reporting

Difficulty: Intermediate
Estimated Time: 2–3 Hours
Lab Type: PenTest+ Capstone Lab
Primary Focus: End-to-End Penetration Testing Methodology
Technical Depth: Low — methodology and professional workflow focused
Environment: Authorized simulated enterprise environment

This is the final PenTest+ lab.

Instead of concentrating on one particular technology or vulnerability, you will bring together the complete penetration-testing lifecycle.

You will work through:

Scoping → Reconnaissance → Testing → Evidence → Risk → Remediation → Reporting

Your goal is to think and operate like a professional penetration tester conducting an engagement for a client.

By completing this lab, you should understand how to:

  • Define penetration-testing scope.

  • Establish Rules of Engagement.

  • Identify the organization’s attack surface.

  • Organize security testing.

  • Validate security findings.

  • Collect defensible evidence.

  • Determine business impact.

  • Prioritize risk.

  • Recommend remediation.

  • Produce a professional penetration-test report.

  • Conduct an engagement closeout.

GoHackersCloud Financial Services is preparing for an external security review.

Management wants an independent assessment of its security posture before an upcoming compliance audit.

The organization operates:

  • Public-facing applications

  • Corporate networks

  • Employee systems

  • Cloud services

  • Identity infrastructure

  • Business applications

  • Security monitoring systems

You have been assigned as the penetration tester.

Management wants answers to five questions:

  1. What security weaknesses exist?

  2. Which weaknesses could realistically be exploited?

  3. What business systems could be affected?

  4. Which risks should be addressed first?

  5. What should the organization do to reduce those risks?

Your responsibility is to conduct the assessment and present those answers professionally.

Start by understanding why the penetration test is being performed.

Meet with the simulated client and identify:

Business Objective

Why does the organization require the assessment?

Possible reasons include:

  • Security assurance

  • Compliance preparation

  • New system deployment

  • Customer requirements

  • Risk management

  • Security-program improvement

A professional penetration test starts with the business objective, not with security tools.

Determine exactly what belongs inside the assessment.

Create three categories:

Systems and applications explicitly authorized for testing.

Systems that must not be tested.

Systems requiring additional approval before testing.

Your scope document should answer:

  • What environments are included?

  • What applications are included?

  • What identities may be used?

  • What testing activities are permitted?

  • What activities are prohibited?

The most important rule is:

Authorization determines the boundary of the penetration test.

Create the Rules of Engagement for the assessment.

Document:

  • Testing period

  • Authorized systems

  • Approved testing activities

  • Prohibited activities

  • Communication contacts

  • Emergency contacts

  • Evidence-handling requirements

  • Incident procedures

  • Stop-testing conditions

Also establish what happens if the penetration tester accidentally discovers something outside the agreed scope.

The correct response is generally:

Stop → Document → Notify → Obtain Authorization

Do not continue testing simply because another system is technically reachable.

Divide the engagement into logical stages.

Your plan should follow:

Planning

Reconnaissance

Discovery

Vulnerability Assessment

Controlled Validation

Impact Assessment

Evidence Collection

Risk Analysis

Reporting

Remediation and Retesting

This gives both the penetration tester and the client a predictable engagement structure.

Begin by building an understanding of the organization’s attack surface.

Identify relevant information about:

  • Internet-facing systems

  • Applications

  • Domains

  • Cloud services

  • Identity infrastructure

  • Business services

The objective is to answer:

What could an external attacker potentially discover about this organization?

Record findings in a reconnaissance worksheet.

At this stage, findings are observations rather than confirmed vulnerabilities.

Organize discovered assets into categories.

For example:

Asset Category Business Purpose Exposure Priority
Public Website Customer Information Internet Medium
Customer Portal Customer Services Internet High
Identity Platform Authentication Restricted Critical
Cloud Environment Business Workloads Mixed High
Internal Applications Business Operations Internal High

This creates a high-level map of the environment.

Highlight systems that would have significant business consequences if compromised.

Assess the authorized environment for security weaknesses.

Consider areas such as:

  • Network security

  • Application security

  • Identity security

  • Access controls

  • Configuration security

  • Cloud security

  • Security monitoring

  • Patch management

The objective is not to produce the largest possible vulnerability list.

Instead, identify weaknesses that could create meaningful organizational risk.

Not every potential vulnerability should become a penetration-test finding.

For each suspected issue, determine whether it is:

Confirmed

Evidence demonstrates that the weakness exists.

Likely

Evidence strongly suggests the weakness exists.

Unconfirmed

Additional validation would be required.

False Positive

The suspected weakness does not actually exist.

This prevents scanner results and assumptions from becoming inaccurate report findings.

Individual weaknesses become significantly more important when they can be combined.

Consider a hypothetical path:

Internet Exposure

Weak Application Control

Unauthorized Access

Credential Exposure

Privileged System Access

Sensitive Business System

Document possible attack paths supported by your assessment evidence.

This provides context that isolated vulnerability ratings often cannot.

For every significant finding, ask:

What does this mean to the organization?

Consider potential impact on:

Could unauthorized individuals access sensitive information?

Could unauthorized individuals modify systems or information?

Could important business services become unavailable?

Also consider:

  • Financial impact

  • Customer impact

  • Regulatory impact

  • Operational impact

  • Reputational impact

The goal is to translate technical observations into business risk.

Every confirmed finding should have supporting evidence.

Evidence might demonstrate:

  • The affected asset

  • The observed weakness

  • The security control that failed

  • The result of validation

  • The potential impact

Evidence should be:

Relevant

Directly supports the finding.

Minimal

Contains only what is necessary.

Protected

Handled according to engagement requirements.

Reproducible

Another authorized tester should be able to validate the observation.

Avoid collecting unnecessary sensitive information.

Create a central register containing all confirmed findings.

ID Finding Severity Business Impact Priority
PT-01 Critical Access Control Weakness Critical Significant Immediate
PT-02 Excessive Account Privileges High Significant High
PT-03 Weak Security Configuration Medium Moderate Medium
PT-04 Information Exposure Low Limited Low

This register becomes the foundation of the final report.

Not every vulnerability deserves equal attention.

Evaluate findings according to:

  • Likelihood

  • Exploitability

  • Asset importance

  • Privileges obtained

  • Data sensitivity

  • Existing controls

  • Business impact

Use a simple model:

Risk = Likelihood × Impact

Then classify findings:

Requires immediate attention.

Significant risk requiring prioritized remediation.

Meaningful weakness requiring planned remediation.

Limited risk or defense-in-depth improvement.

Observation or security-improvement opportunity.

Phase 14 — Develop Remediation Recommendations

Section titled “Phase 14 — Develop Remediation Recommendations”

Every significant finding should include an actionable recommendation.

Avoid recommendations such as:

“Improve security.”

Instead explain the control objective.

Recommendations may include:

  • Strengthen access controls.

  • Apply least privilege.

  • Reduce unnecessary exposure.

  • Improve network segmentation.

  • Strengthen authentication.

  • Correct insecure configurations.

  • Improve patch management.

  • Protect sensitive information.

  • Strengthen monitoring and alerting.

  • Review privileged accounts.

Where possible, divide recommendations into:

Immediate Actions

Reduce immediate exposure.

Short-Term Improvements

Correct the underlying vulnerability.

Long-Term Improvements

Strengthen the broader security architecture.

The executive summary is written for leadership.

Avoid unnecessary technical details.

It should explain:

Why the penetration test was conducted.

What the assessment indicates about organizational security.

What the most important security concerns are.

Why leadership should care.

What should happen next.

A good executive summary allows a senior leader to understand the engagement without reading the technical findings.

Phase 16 — Build the Technical Findings Section

Section titled “Phase 16 — Build the Technical Findings Section”

Each confirmed finding should follow a consistent structure.

PT-01

Clear description of the security issue.

Critical / High / Medium / Low / Informational

Identify the relevant system or application.

Explain the weakness.

Provide supporting assessment evidence.

Explain what the weakness could mean to the organization.

Explain how the organization should address the issue.

Immediate / High / Planned / Improvement

This structure makes findings easier for security and engineering teams to act upon.

Phase 17 — Create the Executive Risk View

Section titled “Phase 17 — Create the Executive Risk View”

Summarize findings for management.

For example:

Severity Findings Management Response
Critical 1 Immediate Action
High 3 Priority Remediation
Medium 5 Planned Remediation
Low 4 Security Improvement
Informational 2 Review

Management should be able to understand the overall security posture quickly.

Phase 18 — Create the Remediation Roadmap

Section titled “Phase 18 — Create the Remediation Roadmap”

Convert findings into a practical improvement plan.

Focus on:

  • Critical vulnerabilities

  • High-risk exposures

  • Compromised or exposed credentials

  • Excessive privileges

  • Immediate configuration problems

Focus on:

  • Architecture improvements

  • Access-control improvements

  • Network segmentation

  • Monitoring improvements

  • Security configuration baselines

Focus on:

  • Security maturity

  • Process improvements

  • Security automation

  • Architecture modernization

  • Continuous testing

  • Security awareness

This makes the penetration-test report useful beyond the assessment itself.

Present the results to the simulated client.

Your presentation should explain:

What was tested

Define the engagement scope.

What was discovered

Summarize significant findings.

What could happen

Explain realistic business impact.

What matters most

Identify the highest-priority risks.

What should happen next

Present the remediation roadmap.

Be prepared to explain technical findings differently depending on your audience.

Executives need risk.

Engineers need remediation.

Security teams need evidence.

A penetration test should not end when the report is delivered.

After remediation, significant findings should be tested again.

Possible retest statuses include:

Remediated

The weakness has been successfully corrected.

Partially Remediated

Risk has been reduced but not eliminated.

Open

The vulnerability remains.

Risk Accepted

Management formally accepts the remaining risk.

Update the final report accordingly.

Your final deliverable should contain:

Engagement name, organization, assessment period, and report classification.

High-level assessment results and major business risks.

Systems and environments included in the engagement.

Testing boundaries and restrictions.

How the assessment was performed.

Overall findings by severity.

How significant weaknesses could combine.

Evidence, impact, severity, and remediation for each vulnerability.

Prioritized corrective actions.

Overall security posture and recommended next steps.

Students should complete the lab with:

1. Penetration Testing Scope

Define authorized and prohibited areas.

2. Rules of Engagement

Document testing boundaries.

3. Attack Surface Map

Identify important systems and exposure.

4. Findings Register

Record validated security weaknesses.

5. Attack Path

Connect relevant weaknesses into a realistic scenario.

6. Risk Assessment

Prioritize findings according to business impact.

7. Remediation Roadmap

Create immediate, short-term, and long-term recommendations.

8. Executive Summary

Explain the assessment for leadership.

9. Final Penetration Test Report

Combine the complete engagement into a professional client deliverable.

For the CompTIA PenTest+ exam, remember the complete engagement lifecycle:

Planning & Scoping

Information Gathering

Vulnerability Identification

Validation

Post-Assessment Activities

Reporting & Communication

Several exam questions may describe a technical situation but actually test whether you understand the professional engagement process.

Remember:

Authorization comes before testing.

Scope determines what you may test.

Rules of Engagement determine how you may test it.

Evidence supports findings.

Impact determines why the finding matters.

Risk helps prioritize remediation.

Reporting communicates the result.

Retesting verifies that remediation worked.

Imagine that you have only five minutes with the organization’s leadership team.

You must answer:

  1. What did we test?

  2. What did we find?

  3. What is our biggest risk?

  4. What could happen if it is not fixed?

  5. What should we fix first?

If your penetration-test report can answer those five questions clearly, you have moved beyond simply finding vulnerabilities and started thinking like a professional security consultant.

The complete penetration-testing lifecycle is:

Scope

→ Understand what you are authorized to assess.

Reconnaissance

→ Understand the attack surface.

Testing

→ Identify and validate security weaknesses.

Evidence

→ Prove what you discovered.

Risk

→ Determine why it matters.

Remediation

→ Explain how the organization should improve.

Reporting

→ Communicate the results to both technical teams and leadership.

A penetration test is ultimately not about how many vulnerabilities you discover.

It is about helping an organization understand:

Where are we exposed, what could happen, what matters most, and what should we do next?

🎯 CompTIA PenTest+ Labs Complete

You have now completed the main practical PenTest+ lab journey:

Reconnaissance → Vulnerability Assessment → Network Testing → Exploitation Assessment → Web Application Assessment → Full Penetration Test & Reporting

The next logical step is to move from individual labs into PenTest+ operational runbooks, where these activities are converted into repeatable procedures that a penetration tester or security consultant can use during real authorized engagements.