mediumMultiple Choice
PT0-002 Practice Question: A client requests that the penetration test…
A client requests that the penetration test report include raw output from the scanning tools used. Where should this output be placed in the report?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the appendices.
Raw tool output is typically included in appendices to avoid cluttering the main findings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
In the appendices.
Why this is correct
Appendices are the standard location for raw tool output and other verbatim evidence because they provide a structured, supplementary space that supports the main narrative without interrupting its readability. This placement preserves the chain of evidence for downstream auditors or remediation teams to verify the raw data against each finding, which is a practice encouraged by reporting standards such as PTES and NIST SP 800-115. Since the client explicitly requested that this data be included in the report, placing it in an appendix satisfies that requirement while keeping the core document focused on analysis and recommendations.
- ✗
As a separate deliverable not included in the report.
Why it's wrong here
Delivering the raw output as a separate file or annex outside the report would technically make it a different deliverable, which contradicts the client's explicit request to have the data included in the penetration test report itself. Even if separate attachments are occasionally acceptable, the scope of this engagement specifically asks for inclusion within the report, so omitting it from the main report structure would be a contractual and compliance failure. Additionally, packaging it separately can cause versioning issues where the report and raw data become disconnected, undermining the evidential completeness of the final deliverable.
- ✗
In the executive summary.
Why it's wrong here
The executive summary is intended for non-technical stakeholders such as executives and board members who need a concise, high-level overview of the organization's risk posture, key vulnerabilities, and strategic recommendations. Embedding rows of raw command outputs, lengthy log excerpts, or full vulnerability scan dumps would obscure the essential business-oriented messages, making the summary unwieldy and difficult for its primary audience to interpret. This section should instead contain synthesized metrics, such as the number of critical findings and overall risk rating, with a reference to the appendix for raw evidence.
- ✗
In the technical findings section, alongside each vulnerability.
Why it's wrong here
The technical findings section should present each vulnerability with a clear, human-readable summary, supporting evidence, proof-of-concept details, impact analysis, and remediation steps; pasting full raw tool output beside each entry would bloat the section and obscure the actual analysis and risk rating. While some abbreviated evidence snippets, such as a single failed HTTP response or a short banner grab, may be appropriate inline, complete raw output is too voluminous and would repeat across multiple findings, making the report unnecessarily redundant. The appropriate pattern is to summarize the key evidence in the findings section and direct the reader to the appendix where the complete, unfiltered output is stored for verification.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.