In addition to monitoring our customer's online security, we provide them with periodic reports about threats and attempts to penetrate their network. What objects do you feel should be included in a security penetration report?
The purpose of this question is to make sure you have experience with security-related reporting and can have a dialog with your customers about their network security and the company's monitoring services. You should answer this question by providing an overview of a good security penetration report.
"A quality Vulnerability and Penetration Testing (VAPT) report should begin with an executive summary which explains the scope, testing process and period the report covers and a general assessment of the client's security status. Next, there should be details of the results of the tests, categorized by the level of the threat (low to high.) There should be a section about the type of tests performed and what they measured. Finally, there should be a set of recommendations for remediation of any threats which were discovered. Some reports also contain screenshots of the test results. "
