Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester has completed the test and…

A penetration tester has completed the test and is preparing the final report. The client asks the tester to include a section that describes the scope, methodology, and tools used. In which section should this information be placed?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Appendices

Appendices are the appropriate place for supplementary information such as scope, methodology, and tools used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Appendices

    Why this is correct

    Appendices are the designated repository for supporting details in a penetration test report, such as raw scan output, command history, screenshots, and proof-of-concept exploit code. These artifacts validate the technical findings without interrupting the narrative flow of the main report. The question's context indicates the tester is organizing supplementary evidence, which explicitly belongs in an appendix section that can be referenced from the body.

  • ✗

    Remediation section

    Why it's wrong here

    The remediation section is action-oriented, providing prioritized fixes, patching instructions, and configuration changes for the vulnerabilities discovered. It is not intended to house raw supporting data like full scan logs or capture files, as that would dilute the clarity of the actionable guidance. The purpose of this section is to tell the client exactly what to do, not to re-demonstrate the testing process.

  • ✗

    Technical findings

    Why it's wrong here

    The technical findings section presents each vulnerability in a structured narrative, including impact analysis, severity ratings, and concise proof of exploitability. While it references supporting evidence, it does not include large volumes of raw data or unprocessed artifacts. Placing exhaustive supporting details here would overwhelm the reader and obscure the key technical issues that need attention, so those details are instead relegated to appendices.

  • ✗

    Executive summary

    Why it's wrong here

    The executive summary is a high-level, non-technical overview intended for management, highlighting business risk, overall exposure, and strategic recommendations. It deliberately omits deep technical detail and raw data to remain concise and accessible to non-technical stakeholders. Supporting details such as logs and screenshots would be inappropriate in this summary, as they are meant for technical audiences and belong in the appendix.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.