An intern copies a blank penetration-test template with exploit narrative, proof-of-concept, and CVSS sections for a parks vendor OSINT memo. What should the analyst use instead?
Select an answer to reveal the explanation.
Short Explanation
A pentest template on an OSINT job is like bringing a crash-test checklist to a library research paper. Nobody asked for exploits or scores; they asked where the public facts came from. Use sources, methods, findings, and gaps—the OSINT family, not the attack-report family.
Full Explanation
OSINT reporting documents public-source collection, methodology, sourced findings, and unanswered gaps. Exploit narratives, proof-of-concept sections, CVSS, wireless attack appendices, and malware timelines belong to other disciplines and are out of PORP scope. Filling those blanks with guesses manufactures an attack story the city did not authorize. Start from an OSINT template so the parks memo can be reproduced from public artifacts.