CompTIA PenTest+ PT0-002 Practice Question
When determining how long to retain a penetration test report, which consideration aligns BEST with industry best practices regarding data retention policies?
Reports should be kept for as long as specified by the organization's data retention policy.
Reports should be kept indefinitely for historical comparison.
Reports should be kept for a 'safe' short-term duration of 30 days, then discarded.
Retention should be based on the personal preference of the penetration tester.