Practice vocabulary for writing effective bug bounty reports: proof of concept, reproduction steps, impact assessment, scope clarification, and HackerOne submissions.
0 / 10 completed
1 / 10
The working exploit or demonstration code that proves a vulnerability is real and exploitable is called:
The report includes proof of concept (PoC) — triagers need to reproduce the issue; a working PoC dramatically increases report credibility and speed of triage.
2 / 10
The section of a bug bounty report that walks the triager through how to reproduce the issue is called:
Steps to reproduce — clear numbered steps (1. Navigate to X, 2. Enter Y, 3. Observe Z) are essential for the security team to validate the report.
3 / 10
The section of a bug bounty report that explains what an attacker could do if they exploited this vulnerability is called:
The potential impact vocabulary includes phrases like 'an attacker could read all user data', 'bypass authentication', or 'achieve remote code execution'.
4 / 10
When a report explains why a specific behavior is not eligible under the bug bounty rules, this section is called:
The out-of-scope clarification — if you're reporting something adjacent to scope, explicitly noting what's in/out-of-scope shows professionalism.
5 / 10
When a researcher submits a report through a company's HackerOne program, they would say:
I'm reporting this through your HackerOne program — specifying the platform helps the security team route the report correctly and confirms you followed the proper channel.
6 / 10
Alice, a security researcher, is submitting a bug bounty report for a SQL injection vulnerability she found in the WebAppX API. In her initial Slack message to the team, she describes the vulnerability as 'easily exploitable' and provides a working payload. Which of the following phrases best captures the core purpose of this initial communication?
The correct answer highlights the key element: providing demonstrable evidence. A strong initial message in a bug bounty context focuses on presenting a working exploit or proof-of-concept. Options A and D are too demanding initially, while option C accurately reflects the purpose of sharing a functional payload for investigation. Misconceptions often involve framing the issue as purely needing 'attention' without concrete evidence.
7 / 10
You're reviewing a pull request submitted by Ben to fix an XSS vulnerability in the User Profile Service. Ben's PR description reads: 'Added input sanitization to prevent reflected XSS.' Which of the following best describes the *most* appropriate follow-up comment you should leave on this PR?
The best response focuses on seeking clarification and technical detail. Ben's description is high-level; a good code review comment should probe for specifics regarding the sanitization process (techniques, rationale). Options A are too general and potentially unhelpful, while option D introduces an unrelated concern. It's crucial to understand *how* the vulnerability was addressed, not just that it was.
8 / 10
Chloe has discovered a race condition in the Order Processing System. Her bug bounty report includes a detailed analysis of the system's architecture and timing. Which section of the report would be MOST suitable for describing the potential consequences if an attacker successfully exploited this race condition?
The 'Impact Assessment' is specifically designed to address what an attacker *could* do. While other sections are important, this one focuses on the ramifications of the vulnerability – how it could be exploited to gain unauthorized access, modify data, or disrupt service. A clear understanding of potential impact is a critical component of any effective bug bounty report.
9 / 10
David submits a bug bounty report detailing a denial-of-service vulnerability in the Payment Gateway API. The report includes steps to reproduce the issue but states: 'Due to the nature of this vulnerability, it is not eligible for a reward under Honecker's Policy v2.3 section 4.2 – 'Exploitation of service disruption leading to financial loss.' Which term best describes David's justification?
David is correctly citing a policy exclusion. The report identifies a vulnerability that, according to the company's rules, doesn't qualify for a bounty because it involves exploiting service disruption leading to *financial loss*. This aligns with common bug bounty policies that restrict rewards for vulnerabilities with severe financial consequences. Options A and D are incorrect as they don't relate to policy exclusions.
10 / 10
Eve is reporting a vulnerability through HackerOne. In her initial submission, she states: 'I've found a way to bypass the rate limiting on the API endpoint. The system crashes when I send too many requests.' What would Eve most likely say to the triager *next*?
Following up with specific data (the exact number of requests) is crucial for the triager to properly assess the vulnerability's severity and potential impact. This allows them to determine whether it meets the criteria for a bounty reward. Option D is a standard request but doesn't address the immediate need for technical information.
What will I learn from the "Bug Bounty Report Writing Vocabulary" exercise?
Practice vocabulary for writing effective bug bounty reports: proof of concept, reproduction steps, impact assessment, scope clarification, and HackerOne submissions.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall required.
How many questions are in this exercise?
This set contains 10 multiple-choice questions, each with a detailed explanation shown after you answer.
Do I need to create an account to track my progress?
No account is required. Your progress bar and score reset each time you reload the page, but you can retry the exercise as many times as you like.
Who is this Security Disclosure Language exercise for?
This exercise is built for IT professionals and non-native English speakers who need to read, write, and discuss security disclosure language topics confidently at work.
What happens if I answer a question incorrectly?
You will see the correct answer highlighted along with a detailed explanation of why it is correct -- so every wrong answer becomes a learning moment, not just a lost point.
Can I retry this exercise?
Yes -- click "Try again" on the results screen at any time to reset your score and go through all the questions again.
How long does this exercise take to complete?
Most learners finish all 10 questions in under 10 minutes, since each question is answered by clicking a single option.
Where can I find more Security Disclosure Language exercises?
See the full Security Disclosure Language exercises hub for more vocabulary drills on this topic.
Is this exercise mobile-friendly?
Yes -- the exercise works on any device with a modern browser, including phones and tablets, with no app download required.