GIAC Penetration Tester (GPEN) — Question 68
Why is OSSTMM beneficial to the pen tester?
Answer options
- A. It provides a legal and contractual framework for testing
- B. It provides in-depth knowledge on tools
- C. It provides report templates
- D. It includes an automated testing engine similar to Metasploit
Correct answer: C
Explanation
The correct answer is C because OSSTMM indeed provides standardized report templates that help streamline documentation for pen testers. Options A, B, and D are incorrect as OSSTMM does not primarily focus on legal frameworks, detailed tool knowledge, or automated testing engines.