mediumMultiple Choice
PT0-002 Practice Question: A client review of a penetration test report…
A client review of a penetration test report reveals confusion about why a particular vulnerability exists. The client's security engineer wants to understand the root cause and the exact steps to reproduce the issue. Which section of the report should the tester point the engineer to?
⚠ Common exam trap
Candidates often confuse the purpose of the Methodology section (which describes the testing process) with the Technical Findings section (which contains the actual vulnerability details and reproduction steps).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Technical Findings
The Technical Findings section provides the detailed, step-by-step reproduction steps and root cause analysis that the security engineer needs. This section includes specific commands, payloads, and configurations that led to the vulnerability, enabling the engineer to understand and verify the issue. The Executive Summary and Methodology sections do not contain this level of technical detail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Executive Summary
Why it's wrong here
The Executive Summary is written for management and business stakeholders, providing a high-level overview of goals, scope, critical risks, and executive-level recommendations. It deliberately avoids deep technical jargon, root-cause analysis, and step-by-step reproduction instructions, so it cannot resolve confusion about specific vulnerability mechanics. A reader seeking technical clarity should consult the Technical Findings section instead.
- ✓
Technical Findings
Why this is correct
The Technical Findings section is the authoritative body of the report, containing in-depth vulnerability descriptions, affected hosts and components, root cause analysis, step-by-step reproduction procedures, and tailored remediation guidance. It gives a security engineer or developer everything needed to understand precisely why a flaw exists and how to verify and fix it. When a client is confused about a specific vulnerability's technical details, this is the section that directly addresses that confusion.
- ✗
Methodology
Why it's wrong here
The Methodology section outlines the engagement process: scoping, reconnaissance techniques, vulnerability scanning, exploitation attempts, and post-exploitation activities, along with the tools used. It explains how testing was performed and why certain tests were selected, but it does not contain details about individual findings, such as a vulnerability's root cause or reproduction steps. Therefore, it cannot resolve confusion about a particular technical issue described in the report.
- ✗
Risk Rating Appendix
Why it's wrong here
The Risk Rating Appendix provides severity classifications using frameworks like CVSS, including base metrics, threat likelihood, and business impact scores. While it assigns each finding a quantitative risk value, it omits the underlying technical explanation, root cause, or verification steps needed to understand the vulnerability itself. It is a reference for prioritization, not a source of technical clarity, so it would not address confusion about a finding's specifics.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.