Lab 06 Full Penetration Test and Professional Reporting
Mission Information
Section titled “Mission Information”Difficulty: Intermediate
Estimated Time: 2–3 Hours
Lab Type: PenTest+ Capstone Lab
Primary Focus: End-to-End Penetration Testing Methodology
Technical Depth: Low — methodology and professional workflow focused
Environment: Authorized simulated enterprise environment
Mission Objective
Section titled “Mission Objective”This is the final PenTest+ lab.
Instead of concentrating on one particular technology or vulnerability, you will bring together the complete penetration-testing lifecycle.
You will work through:
Scoping → Reconnaissance → Testing → Evidence → Risk → Remediation → Reporting
Your goal is to think and operate like a professional penetration tester conducting an engagement for a client.
By completing this lab, you should understand how to:
-
Define penetration-testing scope.
-
Establish Rules of Engagement.
-
Identify the organization’s attack surface.
-
Organize security testing.
-
Validate security findings.
-
Collect defensible evidence.
-
Determine business impact.
-
Prioritize risk.
-
Recommend remediation.
-
Produce a professional penetration-test report.
-
Conduct an engagement closeout.
Scenario
Section titled “Scenario”GoHackersCloud Financial Services is preparing for an external security review.
Management wants an independent assessment of its security posture before an upcoming compliance audit.
The organization operates:
-
Public-facing applications
-
Corporate networks
-
Employee systems
-
Cloud services
-
Identity infrastructure
-
Business applications
-
Security monitoring systems
You have been assigned as the penetration tester.
Management wants answers to five questions:
-
What security weaknesses exist?
-
Which weaknesses could realistically be exploited?
-
What business systems could be affected?
-
Which risks should be addressed first?
-
What should the organization do to reduce those risks?
Your responsibility is to conduct the assessment and present those answers professionally.
Phase 1 — Understand the Engagement
Section titled “Phase 1 — Understand the Engagement”Start by understanding why the penetration test is being performed.
Meet with the simulated client and identify:
Business Objective
Why does the organization require the assessment?
Possible reasons include:
-
Security assurance
-
Compliance preparation
-
New system deployment
-
Customer requirements
-
Risk management
-
Security-program improvement
A professional penetration test starts with the business objective, not with security tools.
Phase 2 — Define the Scope
Section titled “Phase 2 — Define the Scope”Determine exactly what belongs inside the assessment.
Create three categories:
In Scope
Section titled “In Scope”Systems and applications explicitly authorized for testing.
Out of Scope
Section titled “Out of Scope”Systems that must not be tested.
Conditional Scope
Section titled “Conditional Scope”Systems requiring additional approval before testing.
Your scope document should answer:
-
What environments are included?
-
What applications are included?
-
What identities may be used?
-
What testing activities are permitted?
-
What activities are prohibited?
The most important rule is:
Authorization determines the boundary of the penetration test.
Phase 3 — Establish Rules of Engagement
Section titled “Phase 3 — Establish Rules of Engagement”Create the Rules of Engagement for the assessment.
Document:
-
Testing period
-
Authorized systems
-
Approved testing activities
-
Prohibited activities
-
Communication contacts
-
Emergency contacts
-
Evidence-handling requirements
-
Incident procedures
-
Stop-testing conditions
Also establish what happens if the penetration tester accidentally discovers something outside the agreed scope.
The correct response is generally:
Stop → Document → Notify → Obtain Authorization
Do not continue testing simply because another system is technically reachable.
Phase 4 — Create the Testing Plan
Section titled “Phase 4 — Create the Testing Plan”Divide the engagement into logical stages.
Your plan should follow:
Planning
↓
Reconnaissance
↓
Discovery
↓
Vulnerability Assessment
↓
Controlled Validation
↓
Impact Assessment
↓
Evidence Collection
↓
Risk Analysis
↓
Reporting
↓
Remediation and Retesting
This gives both the penetration tester and the client a predictable engagement structure.
Phase 5 — Perform Reconnaissance
Section titled “Phase 5 — Perform Reconnaissance”Begin by building an understanding of the organization’s attack surface.
Identify relevant information about:
-
Internet-facing systems
-
Applications
-
Domains
-
Cloud services
-
Identity infrastructure
-
Business services
The objective is to answer:
What could an external attacker potentially discover about this organization?
Record findings in a reconnaissance worksheet.
At this stage, findings are observations rather than confirmed vulnerabilities.
Phase 6 — Build the Attack Surface Map
Section titled “Phase 6 — Build the Attack Surface Map”Organize discovered assets into categories.
For example:
| Asset Category | Business Purpose | Exposure | Priority |
|---|---|---|---|
| Public Website | Customer Information | Internet | Medium |
| Customer Portal | Customer Services | Internet | High |
| Identity Platform | Authentication | Restricted | Critical |
| Cloud Environment | Business Workloads | Mixed | High |
| Internal Applications | Business Operations | Internal | High |
This creates a high-level map of the environment.
Highlight systems that would have significant business consequences if compromised.
Phase 7 — Perform Security Assessment
Section titled “Phase 7 — Perform Security Assessment”Assess the authorized environment for security weaknesses.
Consider areas such as:
-
Network security
-
Application security
-
Identity security
-
Access controls
-
Configuration security
-
Cloud security
-
Security monitoring
-
Patch management
The objective is not to produce the largest possible vulnerability list.
Instead, identify weaknesses that could create meaningful organizational risk.
Phase 8 — Validate Findings
Section titled “Phase 8 — Validate Findings”Not every potential vulnerability should become a penetration-test finding.
For each suspected issue, determine whether it is:
Confirmed
Evidence demonstrates that the weakness exists.
Likely
Evidence strongly suggests the weakness exists.
Unconfirmed
Additional validation would be required.
False Positive
The suspected weakness does not actually exist.
This prevents scanner results and assumptions from becoming inaccurate report findings.
Phase 9 — Identify Attack Paths
Section titled “Phase 9 — Identify Attack Paths”Individual weaknesses become significantly more important when they can be combined.
Consider a hypothetical path:
Internet Exposure
↓
Weak Application Control
↓
Unauthorized Access
↓
Credential Exposure
↓
Privileged System Access
↓
Sensitive Business System
Document possible attack paths supported by your assessment evidence.
This provides context that isolated vulnerability ratings often cannot.
Phase 10 — Determine Business Impact
Section titled “Phase 10 — Determine Business Impact”For every significant finding, ask:
What does this mean to the organization?
Consider potential impact on:
Confidentiality
Section titled “Confidentiality”Could unauthorized individuals access sensitive information?
Integrity
Section titled “Integrity”Could unauthorized individuals modify systems or information?
Availability
Section titled “Availability”Could important business services become unavailable?
Also consider:
-
Financial impact
-
Customer impact
-
Regulatory impact
-
Operational impact
-
Reputational impact
The goal is to translate technical observations into business risk.
Phase 11 — Collect Evidence
Section titled “Phase 11 — Collect Evidence”Every confirmed finding should have supporting evidence.
Evidence might demonstrate:
-
The affected asset
-
The observed weakness
-
The security control that failed
-
The result of validation
-
The potential impact
Evidence should be:
Relevant
Directly supports the finding.
Minimal
Contains only what is necessary.
Protected
Handled according to engagement requirements.
Reproducible
Another authorized tester should be able to validate the observation.
Avoid collecting unnecessary sensitive information.
Phase 12 — Create the Findings Register
Section titled “Phase 12 — Create the Findings Register”Create a central register containing all confirmed findings.
| ID | Finding | Severity | Business Impact | Priority |
|---|---|---|---|---|
| PT-01 | Critical Access Control Weakness | Critical | Significant | Immediate |
| PT-02 | Excessive Account Privileges | High | Significant | High |
| PT-03 | Weak Security Configuration | Medium | Moderate | Medium |
| PT-04 | Information Exposure | Low | Limited | Low |
This register becomes the foundation of the final report.
Phase 13 — Prioritize Risk
Section titled “Phase 13 — Prioritize Risk”Not every vulnerability deserves equal attention.
Evaluate findings according to:
-
Likelihood
-
Exploitability
-
Asset importance
-
Privileges obtained
-
Data sensitivity
-
Existing controls
-
Business impact
Use a simple model:
Risk = Likelihood × Impact
Then classify findings:
Critical
Section titled “Critical”Requires immediate attention.
Significant risk requiring prioritized remediation.
Medium
Section titled “Medium”Meaningful weakness requiring planned remediation.
Limited risk or defense-in-depth improvement.
Informational
Section titled “Informational”Observation or security-improvement opportunity.
Phase 14 — Develop Remediation Recommendations
Section titled “Phase 14 — Develop Remediation Recommendations”Every significant finding should include an actionable recommendation.
Avoid recommendations such as:
“Improve security.”
Instead explain the control objective.
Recommendations may include:
-
Strengthen access controls.
-
Apply least privilege.
-
Reduce unnecessary exposure.
-
Improve network segmentation.
-
Strengthen authentication.
-
Correct insecure configurations.
-
Improve patch management.
-
Protect sensitive information.
-
Strengthen monitoring and alerting.
-
Review privileged accounts.
Where possible, divide recommendations into:
Immediate Actions
Reduce immediate exposure.
Short-Term Improvements
Correct the underlying vulnerability.
Long-Term Improvements
Strengthen the broader security architecture.
Phase 15 — Build the Executive Summary
Section titled “Phase 15 — Build the Executive Summary”The executive summary is written for leadership.
Avoid unnecessary technical details.
It should explain:
Assessment Objective
Section titled “Assessment Objective”Why the penetration test was conducted.
Overall Security Posture
Section titled “Overall Security Posture”What the assessment indicates about organizational security.
Major Risks
Section titled “Major Risks”What the most important security concerns are.
Business Impact
Section titled “Business Impact”Why leadership should care.
Priority Actions
Section titled “Priority Actions”What should happen next.
A good executive summary allows a senior leader to understand the engagement without reading the technical findings.
Phase 16 — Build the Technical Findings Section
Section titled “Phase 16 — Build the Technical Findings Section”Each confirmed finding should follow a consistent structure.
Finding ID
Section titled “Finding ID”PT-01
Finding Title
Section titled “Finding Title”Clear description of the security issue.
Severity
Section titled “Severity”Critical / High / Medium / Low / Informational
Affected Asset
Section titled “Affected Asset”Identify the relevant system or application.
Description
Section titled “Description”Explain the weakness.
Evidence
Section titled “Evidence”Provide supporting assessment evidence.
Business Impact
Section titled “Business Impact”Explain what the weakness could mean to the organization.
Recommendation
Section titled “Recommendation”Explain how the organization should address the issue.
Remediation Priority
Section titled “Remediation Priority”Immediate / High / Planned / Improvement
This structure makes findings easier for security and engineering teams to act upon.
Phase 17 — Create the Executive Risk View
Section titled “Phase 17 — Create the Executive Risk View”Summarize findings for management.
For example:
| Severity | Findings | Management Response |
|---|---|---|
| Critical | 1 | Immediate Action |
| High | 3 | Priority Remediation |
| Medium | 5 | Planned Remediation |
| Low | 4 | Security Improvement |
| Informational | 2 | Review |
Management should be able to understand the overall security posture quickly.
Phase 18 — Create the Remediation Roadmap
Section titled “Phase 18 — Create the Remediation Roadmap”Convert findings into a practical improvement plan.
0–30 Days
Section titled “0–30 Days”Focus on:
-
Critical vulnerabilities
-
High-risk exposures
-
Compromised or exposed credentials
-
Excessive privileges
-
Immediate configuration problems
30–90 Days
Section titled “30–90 Days”Focus on:
-
Architecture improvements
-
Access-control improvements
-
Network segmentation
-
Monitoring improvements
-
Security configuration baselines
90+ Days
Section titled “90+ Days”Focus on:
-
Security maturity
-
Process improvements
-
Security automation
-
Architecture modernization
-
Continuous testing
-
Security awareness
This makes the penetration-test report useful beyond the assessment itself.
Phase 19 — Conduct the Client Debrief
Section titled “Phase 19 — Conduct the Client Debrief”Present the results to the simulated client.
Your presentation should explain:
What was tested
Define the engagement scope.
What was discovered
Summarize significant findings.
What could happen
Explain realistic business impact.
What matters most
Identify the highest-priority risks.
What should happen next
Present the remediation roadmap.
Be prepared to explain technical findings differently depending on your audience.
Executives need risk.
Engineers need remediation.
Security teams need evidence.
Phase 20 — Plan the Retest
Section titled “Phase 20 — Plan the Retest”A penetration test should not end when the report is delivered.
After remediation, significant findings should be tested again.
Possible retest statuses include:
Remediated
The weakness has been successfully corrected.
Partially Remediated
Risk has been reduced but not eliminated.
Open
The vulnerability remains.
Risk Accepted
Management formally accepts the remaining risk.
Update the final report accordingly.
Final Penetration Test Report
Section titled “Final Penetration Test Report”Your final deliverable should contain:
1. Cover Page
Section titled “1. Cover Page”Engagement name, organization, assessment period, and report classification.
2. Executive Summary
Section titled “2. Executive Summary”High-level assessment results and major business risks.
3. Scope
Section titled “3. Scope”Systems and environments included in the engagement.
4. Rules of Engagement
Section titled “4. Rules of Engagement”Testing boundaries and restrictions.
5. Methodology
Section titled “5. Methodology”How the assessment was performed.
6. Risk Summary
Section titled “6. Risk Summary”Overall findings by severity.
7. Attack Path Summary
Section titled “7. Attack Path Summary”How significant weaknesses could combine.
8. Detailed Findings
Section titled “8. Detailed Findings”Evidence, impact, severity, and remediation for each vulnerability.
9. Remediation Roadmap
Section titled “9. Remediation Roadmap”Prioritized corrective actions.
10. Conclusion
Section titled “10. Conclusion”Overall security posture and recommended next steps.
Final Lab Deliverables
Section titled “Final Lab Deliverables”Students should complete the lab with:
1. Penetration Testing Scope
Define authorized and prohibited areas.
2. Rules of Engagement
Document testing boundaries.
3. Attack Surface Map
Identify important systems and exposure.
4. Findings Register
Record validated security weaknesses.
5. Attack Path
Connect relevant weaknesses into a realistic scenario.
6. Risk Assessment
Prioritize findings according to business impact.
7. Remediation Roadmap
Create immediate, short-term, and long-term recommendations.
8. Executive Summary
Explain the assessment for leadership.
9. Final Penetration Test Report
Combine the complete engagement into a professional client deliverable.
PenTest+ Exam Perspective
Section titled “PenTest+ Exam Perspective”For the CompTIA PenTest+ exam, remember the complete engagement lifecycle:
Planning & Scoping
↓
Information Gathering
↓
Vulnerability Identification
↓
Validation
↓
Post-Assessment Activities
↓
Reporting & Communication
Several exam questions may describe a technical situation but actually test whether you understand the professional engagement process.
Remember:
Authorization comes before testing.
Scope determines what you may test.
Rules of Engagement determine how you may test it.
Evidence supports findings.
Impact determines why the finding matters.
Risk helps prioritize remediation.
Reporting communicates the result.
Retesting verifies that remediation worked.
Final Capstone Challenge
Section titled “Final Capstone Challenge”Imagine that you have only five minutes with the organization’s leadership team.
You must answer:
-
What did we test?
-
What did we find?
-
What is our biggest risk?
-
What could happen if it is not fixed?
-
What should we fix first?
If your penetration-test report can answer those five questions clearly, you have moved beyond simply finding vulnerabilities and started thinking like a professional security consultant.
Key Takeaway
Section titled “Key Takeaway”The complete penetration-testing lifecycle is:
Scope
→ Understand what you are authorized to assess.
Reconnaissance
→ Understand the attack surface.
Testing
→ Identify and validate security weaknesses.
Evidence
→ Prove what you discovered.
Risk
→ Determine why it matters.
Remediation
→ Explain how the organization should improve.
Reporting
→ Communicate the results to both technical teams and leadership.
A penetration test is ultimately not about how many vulnerabilities you discover.
It is about helping an organization understand:
Where are we exposed, what could happen, what matters most, and what should we do next?
What’s Next?
Section titled “What’s Next?”🎯 CompTIA PenTest+ Labs Complete
You have now completed the main practical PenTest+ lab journey:
Reconnaissance → Vulnerability Assessment → Network Testing → Exploitation Assessment → Web Application Assessment → Full Penetration Test & Reporting
The next logical step is to move from individual labs into PenTest+ operational runbooks, where these activities are converted into repeatable procedures that a penetration tester or security consultant can use during real authorized engagements.