easyMultiple Choice
PT0-002 Practice Question: A penetration tester has completed the testing…
A penetration tester has completed the testing phase and is preparing the final report for the client's board of directors. The board members are non-technical and need to understand the overall security posture and business risk. Which section of the report should the tester focus on for this audience?
⚠ Common exam trap
CompTIA often tests the candidate's ability to distinguish between report sections for different audiences, trapping those who think all findings must be presented in full detail regardless of the reader's technical level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An executive summary highlighting key risks and business impact
The board of directors requires a high-level overview that translates technical findings into business risk. An executive summary achieves this by focusing on key risks, potential financial or reputational impact, and strategic recommendations, avoiding technical jargon like CVSS scores or command logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A detailed list of all vulnerabilities with CVSS scores and exploitation steps
Why it's wrong here
Presenting a detailed inventory of vulnerabilities with CVSS scores and step-by-step exploitation procedures overwhelms non-technical executives and exposes sensitive technical information. Such granularity is intended for the technical report, where remediation teams need reproducible steps and scoring to prioritize patches. The executive summary should instead aggregate these findings into high-level risk statements that link to business impact, not enumerate technical specifics.
- ✓
An executive summary highlighting key risks and business impact
Why this is correct
An executive summary that highlights key risks and business impact is the correct choice because it translates technical findings into the language of business, focusing on potential financial, operational, and reputational consequences. This concise overview helps non-technical decision-makers understand the urgency and allocate resources appropriately, without needing to sift through exploit details. It is the top section of a pentest report, setting the tone and driving strategic action.
- ✗
A complete log of all commands executed during the test
Why it's wrong here
A complete log of all commands executed during the test is raw machine-generated data, often containing syntax, directory paths, and tool-specific arguments that have no intrinsic meaning to a board of directors. It may also reveal attack methodology that should remain confidential within the technical appendices. Including this in an executive summary would obfuscate the key message and create an unnecessary data-dump for an audience that needs conclusions, not command history.
- ✗
A network diagram showing all discovered hosts and open ports
Why it's wrong here
A network diagram showing all discovered hosts and open ports is a useful technical artifact, but it presents attack surface as a static picture, not as prioritized business risk. Executives require an understanding of which assets matter to the organization and what the exposure could cost them, rather than a visual inventory of IP addresses and port numbers. Such diagrams are better placed in the technical report or appendix, where network engineers and system administrators can act on them.
Go deeper
Related to this question
Learn chapter
Red Team Exercises vs Penetration Tests
Key term
CVSS
The Common Vulnerability Scoring System (CVSS) is a standardized framework used to rate the severity of security vulnerabilities on a scale from 0 to 10.
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.