Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester has completed an engagement…

A penetration tester has completed an engagement and needs to present findings to a mixed audience of technical engineers and business executives. Which section of the penetration test report is BEST suited for communicating high-level risk ratings and potential business impact to the non-technical stakeholders?

⚠ Common exam trap

CompTIA often tests the candidate's ability to distinguish between audience-appropriate report sections, and the trap here is assuming that 'Technical Findings' is the most important section for all stakeholders, when in fact the Executive Summary is the primary communication tool for non-technical decision-makers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Executive Summary

The Executive Summary is the correct section because it is specifically designed to communicate high-level risk ratings, business impact, and strategic recommendations to non-technical stakeholders such as executives. It avoids technical jargon and focuses on the business context, aligning with the PT0-002 objective of tailoring reports to the audience.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Executive Summary

    Why this is correct

    The Executive Summary is explicitly designed for non-technical leadership, distilling the engagement's key findings into business-oriented language. It presents overall risk severity, quantifies potential business impact (e.g., financial loss, regulatory fines), and prioritizes issues by strategic importance. This high-level view allows executives to make informed risk acceptance decisions without needing to interpret exploit mechanics or raw scan data.

  • ✗

    Technical Findings and Vulnerability Details

    Why it's wrong here

    The Technical Findings and Vulnerability Details section is written for IT staff and application owners who need to reproduce, validate, and mitigate the discovered issues. It includes CVE identifiers, affected product versions, proof-of-concept code, exact attack paths, and network-level evidence, all of which are overwhelming and irrelevant to an executive audience. Because this section focuses on the 'how' rather than the 'so what,' presenting risk ratings here would fail to convey the business impact that the executive summary is meant to communicate.

  • ✗

    Remediation Steps

    Why it's wrong here

    Remediation Steps contain granular, operational instructions—such as specific patches, configuration changes, and architecture adjustments—that require technical expertise to execute. While an executive summary may briefly reference top-priority remediation recommendations, the step-by-step fix list is intended for engineering teams, not as a decision-making overview. Presenting risk ratings and business impact in this section would mix strategic communication with implementation details, diluting the message for non-technical readers.

  • ✗

    Appendix

    Why it's wrong here

    The Appendix is a repository for raw supporting artifacts—full vulnerability scan reports, packet capture excerpts, custom exploitation scripts, and detailed logs—that substantiate the findings for auditors or technical reviewers. It lacks interpretation, prioritization, and business context, making it an inappropriate place to deliver risk ratings or impact assessments. Burying the executive message in the back matter would force key stakeholders to hunt through dense data instead of getting a concise, decision-ready summary.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.