Practise the language of security retesting: verifying fixes, marking findings resolved, partial fixes, and the retest report.
0 / 10 completed
1 / 10
A retest is performed to ___ that reported vulnerabilities have actually been fixed.
The purpose of a retest is to confirm remediation worked in practice, not just that a ticket was closed.
2 / 10
A finding that can no longer be exploited after the fix is marked as ___.
Marking a finding resolved (remediated) records that the retest confirmed the issue is genuinely fixed.
3 / 10
When a fix reduces but doesn't fully eliminate the risk, you report it as a ___ fix.
A partial fix means residual risk remains; the report should explain what's still exploitable and what further work is needed.
4 / 10
If the original issue still works during retest, the finding stays ___.
A finding that reproduces remains open, and the retest report should note that remediation was attempted but unsuccessful.
5 / 10
The deliverable summarising which findings now pass and which still fail is the ___ report.
The retest report gives stakeholders an updated status per finding so they know their true remaining exposure.
6 / 10
Sarah, the security engineer, needs to update the team on a recent vulnerability fix. She writes in Slack: 'Okay, we've retested the login flow after patching the XSS vulnerability. The issue is now marked as resolved.' Which phrase best describes Sarah's statement regarding the status of the vulnerability?
Sarah's statement acknowledges a successful fix but avoids overstating its impact. Using phrases like 'completely and permanently eradicated' can create unrealistic expectations. It's crucial to communicate the level of risk remaining after remediation – in this case, ongoing monitoring is appropriate given the nature of XSS vulnerabilities. Option A is too definitive; option D introduces an unrelated issue.
7 / 10
You're reviewing a code change that addresses a potential race condition in a multithreaded application. After the retest, the bug is no longer reproducible. What should you include in your code review comment to accurately reflect this outcome?
The core of this question tests understanding that a successful retest demonstrates the fix's effectiveness. Saying 'eliminated' provides clear and concise feedback for the developer. Option A contradicts the retest results; option B is too vague; and option D implies ongoing problems where none were found.
8 / 10
David is writing the PR description for a change that resolves a critical security flaw. He states: 'Implemented patch to mitigate potential SQL injection vulnerability.' Which of the following would be MOST appropriate addition to David's description?
David's initial statement is technically correct but lacks crucial context. Adding that the risk has been reduced and highlighting the need for testing and monitoring demonstrates responsible communication regarding security fixes. Option A focuses on unnecessary complexity; option C misrepresents the fix's function; and option D shifts blame.
9 / 10
During a regression retest after applying a hotfix to a user interface component, the original bug is still observed. What should you document in the resulting retest report?
This question assesses understanding of reporting incomplete results. If the original issue persists, it's critical to clearly state that the finding 'remains unresolved'. This directs attention back to the root cause and prevents false confidence in the fix. Options A and B are misleading; option D introduces an unrelated problem.
10 / 10
Maria is preparing a summary report of findings from a retest cycle for a new API endpoint. The report indicates that 80% of the tests now pass, but one test continues to fail due to intermittent network latency. What should Maria include in her conclusion?
Maria's conclusion should be nuanced and honest about the state of the endpoint. While 80% pass rate is positive, highlighting the persistent issue prevents misleading stakeholders. Option A is overly optimistic; option B focuses on a potentially irrelevant metric; and option D shifts responsibility without acknowledging the retest results.
What will I practise in "Retest Communication Language"?
This module focuses on Pentest Communication — real workplace phrasing you'll use on the job. It contains 10 scenario-based multiple-choice questions with instant feedback.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account or sign-up required.
How many questions does this exercise have?
This module includes 10 questions. Each one gives an immediate right/wrong result plus a full explanation of the correct phrasing.
What happens if I answer a question incorrectly?
You'll see the correct answer highlighted straight away, along with a plain-English explanation of why it's right and why the other options don't fit — mistakes are part of the learning here.
Can I retry the exercise if I want a better score?
Yes — use the 'Try again' button on the results screen to reset your score and go through the questions again. There's no limit on attempts.
Who is this Pentest Communication exercise for?
It's aimed at IT professionals with working English who want to sound more natural and precise around pentest communication — useful whether you're preparing for real conversations at work or just building confidence with the vocabulary.
Do I need an account to track my progress?
No account is needed. Your progress through the exercise is tracked locally in your browser for the current session, and you can replay the module at any time.
How is this different from reading a blog article?
This exercise is an interactive drill that tests and reinforces specific phrasing through multiple-choice questions with instant feedback, while blog articles explain concepts and vocabulary in prose. The two work well together.
Where can I find more Pentest Communication exercises?
See the Pentest Communication hub for more modules like this one, or browse the full Exercises page for other IT-English topics.
Can I complete this exercise on my phone?
Yes — every exercise on CoderSlingo is fully responsive and works on phones and tablets, so you can practise anywhere.