Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester has completed a test and is…

A penetration tester has completed a test and is finalizing the report. The client's security team needs to know the exact commands and steps to reproduce a critical remote code execution vulnerability. In which section of the report should this information be primarily documented?

⚠ Common exam trap

Many exam-takers confuse the Methodology section (which describes the general process) with the Findings section (which contains specific exploit details), leading them to incorrectly choose Methodology when the question asks for exact commands and steps to reproduce.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Findings and Remediation

The Findings and Remediation section is the correct place to document the exact commands and steps to reproduce a critical remote code execution vulnerability. This section provides detailed technical evidence, including proof-of-concept (PoC) code, command syntax, and step-by-step reproduction steps, enabling the client's security team to validate and remediate the issue. The Executive Summary is too high-level for such technical details, and the Methodology section describes the overall testing approach, not specific exploit commands.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Executive Summary

    Why it's wrong here

    The Executive Summary is written for non-technical stakeholders such as executives and management, and it must provide a concise, high-level overview of the engagement's purpose, scope, overall risk posture, and business impact. It deliberately omits detailed reproduction steps because the audience does not need to understand, validate, or exploit the technical mechanics of each finding; instead, they need actionable risk metrics such as criticality counts and strategic recommendations. Including step-by-step exploit instructions here would overwhelm readers and distract from the decision-oriented content the summary is meant to convey.

  • ✗

    Methodology

    Why it's wrong here

    The Methodology section describes the overall process and testing approach taken during the penetration test, including the phases such as reconnaissance, scanning, exploitation, and post-exploitation, as well as the tools (e.g., Nmap, Burp Suite, Metasploit) and techniques used. It explains how the test was planned and executed, including scope limitations and rules of engagement, but it does not provide vulnerability-specific reproduction steps. Its purpose is to give the reader the context needed to assess the validity and thoroughness of the test, not to instruct a technical team on how to recreate a particular finding.

  • ✓

    Findings and Remediation

    Why this is correct

    The Findings and Remediation section is the core technical body of the penetration test report where each discovered vulnerability is documented in detail. For every finding, this section includes a severity rating (e.g., CVSS score), the affected systems or endpoints, a thorough step-by-step reproduction procedure, proof-of-concept evidence such as scripts or screenshots, and specific remediation recommendations. This level of detail is essential for the technical team to independently verify the vulnerability, understand the root cause, and apply the correct fix, which is exactly why it is the correct place for reproduction steps.

  • ✗

    Appendix

    Why it's wrong here

    The Appendix contains supplementary reference material that supports the main report, such as raw scan outputs, full packet captures, detailed tool logs, or copy of additional data like discovered credentials or configuration files. While this material can serve as evidence or provide deeper context, it is not the primary location for reproduction steps; those steps must live in the Findings and Remediation section where the technical team will actively read and act on them. Appending reproduction steps would bury critical instructions in what is essentially a backup reference area, making them easy to overlook.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.