Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A client review of a penetration test report…

A client review of a penetration test report reveals confusion about why a particular vulnerability exists. The client's security engineer wants to understand the root cause and the exact steps to reproduce the issue. Which section of the report should the tester point the engineer to?

⚠ Common exam trap

Candidates often confuse the purpose of the Methodology section (which describes the testing process) with the Technical Findings section (which contains the actual vulnerability details and reproduction steps).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Technical Findings

The Technical Findings section provides the detailed, step-by-step reproduction steps and root cause analysis that the security engineer needs. This section includes specific commands, payloads, and configurations that led to the vulnerability, enabling the engineer to understand and verify the issue. The Executive Summary and Methodology sections do not contain this level of technical detail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Executive Summary

    Why it's wrong here

    The Executive Summary is written for management and business stakeholders, providing a high-level overview of goals, scope, critical risks, and executive-level recommendations. It deliberately avoids deep technical jargon, root-cause analysis, and step-by-step reproduction instructions, so it cannot resolve confusion about specific vulnerability mechanics. A reader seeking technical clarity should consult the Technical Findings section instead.

  • ✓

    Technical Findings

    Why this is correct

    The Technical Findings section is the authoritative body of the report, containing in-depth vulnerability descriptions, affected hosts and components, root cause analysis, step-by-step reproduction procedures, and tailored remediation guidance. It gives a security engineer or developer everything needed to understand precisely why a flaw exists and how to verify and fix it. When a client is confused about a specific vulnerability's technical details, this is the section that directly addresses that confusion.

  • ✗

    Methodology

    Why it's wrong here

    The Methodology section outlines the engagement process: scoping, reconnaissance techniques, vulnerability scanning, exploitation attempts, and post-exploitation activities, along with the tools used. It explains how testing was performed and why certain tests were selected, but it does not contain details about individual findings, such as a vulnerability's root cause or reproduction steps. Therefore, it cannot resolve confusion about a particular technical issue described in the report.

  • ✗

    Risk Rating Appendix

    Why it's wrong here

    The Risk Rating Appendix provides severity classifications using frameworks like CVSS, including base metrics, threat likelihood, and business impact scores. While it assigns each finding a quantitative risk value, it omits the underlying technical explanation, root cause, or verification steps needed to understand the vulnerability itself. It is a reference for prioritization, not a source of technical clarity, so it would not address confusion about a finding's specifics.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.