easyMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration tester has submitted the final…
A penetration tester has submitted the final report to the client. The client's legal team requests a separate document that describes the methodology used, but does not include any actual findings or sensitive data. Which type of document should the tester provide?
⚠ Common exam trap
Candidates often confuse the purpose of an executive summary (which summarizes findings) with a methodology-only document, leading them to choose Option A, but the legal team explicitly wants no findings or sensitive data, making a pure methodology document the only correct choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A document describing the testing methodology and scope
The client's legal team specifically requested a document describing the methodology used without any actual findings or sensitive data. Option C, a document describing the testing methodology and scope, directly fulfills this requirement by providing a high-level overview of the penetration testing approach, tools, and boundaries, while excluding all findings, evidence, and sensitive client data. This type of document is often called a 'Methodology Statement' or 'Scope of Work' and is commonly used for legal or compliance purposes to demonstrate due diligence without exposing risk details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A new executive summary that omits the findings
Why it's wrong here
An executive summary is intended to convey high-level findings, risk ratings, and remediation priorities to senior management; removing the findings section would render the document neither a true executive summary nor a useful artifact for legal review. Any residual language about the test's purpose, attack surface, or engagement results could still communicate that exploitable vulnerabilities exist and imply their potential impact. The legal team needs a document that describes only the engagement's parameters, not one that omits findings yet retains other context that invites inference about the test's outcome.
- ✗
A copy of the technical findings with redacted details
Why it's wrong here
Redacting exploit details from technical findings is inadequate because document metadata, hidden rows, and visible vulnerability categories or affected-host names can survive in the file and expose sensitive information. Even if the file is clean, the structure of the findings (e.g., severity ratings, affected system names, or vulnerability titles) allows a knowledgeable reader to infer the specific weaknesses that were uncovered. A separate methodology document that never contains findings in the first place is the only clean way to avoid disclosure, as it eliminates the risk of partial redaction and reconstruction.
- ✓
A document describing the testing methodology and scope
Why this is correct
A methodology and scope document describes the engagement's rules of engagement, such as the approved testing techniques (e.g., credentialed network scanning, web application testing, social engineering), the target IP ranges and domains, the testing schedule, and the authorization constraints. It contains no vulnerability details, exploit paths, or compromised asset information, making it safe for legal counsel to review for contractual compliance. This document demonstrates that the tester operated within the agreed boundaries while keeping all sensitive findings separate from the legal review package.
- ✗
The remediation plan without the exploit steps
Why it's wrong here
A remediation plan is intrinsically vulnerability-centric: it identifies each weakness, its severity rating, and the affected systems so that the IT team can prioritize patching and compensating controls, and it may include references to CVEs or findings IDs even without exploit steps. Legal counsel will view these references as sensitive because they reveal both the existence and the location of exploitable weaknesses within the environment. Therefore, providing the remediation plan—even stripped of attack specifics—fails to give the legal team a clean document that avoids disclosing any vulnerability information.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Evidence
Evidence is any data or documentation that proves an event, action, or condition occurred, crucial for verifying compliance, security incidents, or system changes.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.