easyMultiple Choice
PT0-002 Practice Question: A penetration tester has completed a network…
A penetration tester has completed a network penetration test for a large financial institution. The client has requested a report that includes details for both technical staff and executive management. The tester has written a single report with a technical focus, including raw CLI outputs and exploit code. During the review, the chief information security officer (CISO) expresses confusion about the overall risk posture and wants a concise summary. Which action should the tester take to best address the CISO's concerns?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add an executive summary at the beginning that highlights critical risks and business impact.
Adding an executive summary directly in the report provides a concise, business-oriented overview that addresses the CISO's needs while retaining technical details for staff.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Schedule a meeting to walk through the technical details.
Why it's wrong here
Scheduling a meeting to walk through the technical details is incorrect because the CISO explicitly requested a summary within the written report, not a synchronous verbal briefing. A meeting provides no durable, version-controlled record and cannot be archived with the report for future compliance or audit purposes. Even if the meeting is recorded, it still lacks the searchable, quotable format that a written executive summary embedded in the report would provide, so it fails to satisfy the concrete deliverable.
- ✗
Remove all technical details and replace them with high-level statements.
Why it's wrong here
Removing all technical details and replacing them with high-level statements is incorrect because it would cripple the report's utility for the technical staff who must validate and remediate the findings. Engineers need specific evidence such as affected IP addresses, open ports, vulnerable service versions, and proof-of-concept commands to reproduce and fix issues; without these, they would have to redo penetration testing or request a separate technical report. A best-practice pentest report keeps technical details in a dedicated section or appendix while still providing a high-level executive summary upfront—not one document stripped of all depth.
- ✗
Provide a separate document with only the executive summary.
Why it's wrong here
Providing a separate document with only the executive summary is incorrect because it fragments the deliverable and fails the CISO's request for a summary 'within the report.' Although a standalone summary is better than nothing, it risks divergence from the main report when the latter is updated, and readers are forced to switch between two documents to correlate business impact with technical evidence. Industry guidance such as PTES recommends integrating the executive summary as the first section of the main report, ensuring a single source of truth that all stakeholders can access and reference.
- ✓
Add an executive summary at the beginning that highlights critical risks and business impact.
Why this is correct
Adding an executive summary at the beginning that highlights critical risks and business impact is correct because it directly satisfies the CISO's request while preserving the technical depth below. This structure serves dual audiences: the executive summary translates vulnerabilities into business risk—using metrics like financial impact, regulatory exposure, or likelihood of exploitation—while the technical sections provide the evidence and remediation steps that engineers need. It follows the inverted-pyramid style recommended for penetration test reports and aligns with PTES and NIST SP 800-115 expectations, making it the definitive best practice.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.