Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester has completed the testing…

A penetration tester has completed the testing phase and is preparing the final report for the client's board of directors. The board members are non-technical and need to understand the overall security posture and business risk. Which section of the report should the tester focus on for this audience?

⚠ Common exam trap

CompTIA often tests the candidate's ability to distinguish between report sections for different audiences, trapping those who think all findings must be presented in full detail regardless of the reader's technical level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An executive summary highlighting key risks and business impact

The board of directors requires a high-level overview that translates technical findings into business risk. An executive summary achieves this by focusing on key risks, potential financial or reputational impact, and strategic recommendations, avoiding technical jargon like CVSS scores or command logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A detailed list of all vulnerabilities with CVSS scores and exploitation steps

    Why it's wrong here

    Presenting a detailed inventory of vulnerabilities with CVSS scores and step-by-step exploitation procedures overwhelms non-technical executives and exposes sensitive technical information. Such granularity is intended for the technical report, where remediation teams need reproducible steps and scoring to prioritize patches. The executive summary should instead aggregate these findings into high-level risk statements that link to business impact, not enumerate technical specifics.

  • ✓

    An executive summary highlighting key risks and business impact

    Why this is correct

    An executive summary that highlights key risks and business impact is the correct choice because it translates technical findings into the language of business, focusing on potential financial, operational, and reputational consequences. This concise overview helps non-technical decision-makers understand the urgency and allocate resources appropriately, without needing to sift through exploit details. It is the top section of a pentest report, setting the tone and driving strategic action.

  • ✗

    A complete log of all commands executed during the test

    Why it's wrong here

    A complete log of all commands executed during the test is raw machine-generated data, often containing syntax, directory paths, and tool-specific arguments that have no intrinsic meaning to a board of directors. It may also reveal attack methodology that should remain confidential within the technical appendices. Including this in an executive summary would obfuscate the key message and create an unnecessary data-dump for an audience that needs conclusions, not command history.

  • ✗

    A network diagram showing all discovered hosts and open ports

    Why it's wrong here

    A network diagram showing all discovered hosts and open ports is a useful technical artifact, but it presents attack surface as a static picture, not as prioritized business risk. Executives require an understanding of which assets matter to the organization and what the exposure could cost them, rather than a visual inventory of IP addresses and port numbers. Such diagrams are better placed in the technical report or appendix, where network engineers and system administrators can act on them.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.