Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration tester has submitted the final…

A penetration tester has submitted the final report to the client. The client's legal team requests a separate document that describes the methodology used, but does not include any actual findings or sensitive data. Which type of document should the tester provide?

⚠ Common exam trap

Candidates often confuse the purpose of an executive summary (which summarizes findings) with a methodology-only document, leading them to choose Option A, but the legal team explicitly wants no findings or sensitive data, making a pure methodology document the only correct choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A document describing the testing methodology and scope

The client's legal team specifically requested a document describing the methodology used without any actual findings or sensitive data. Option C, a document describing the testing methodology and scope, directly fulfills this requirement by providing a high-level overview of the penetration testing approach, tools, and boundaries, while excluding all findings, evidence, and sensitive client data. This type of document is often called a 'Methodology Statement' or 'Scope of Work' and is commonly used for legal or compliance purposes to demonstrate due diligence without exposing risk details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A new executive summary that omits the findings

    Why it's wrong here

    An executive summary is intended to convey high-level findings, risk ratings, and remediation priorities to senior management; removing the findings section would render the document neither a true executive summary nor a useful artifact for legal review. Any residual language about the test's purpose, attack surface, or engagement results could still communicate that exploitable vulnerabilities exist and imply their potential impact. The legal team needs a document that describes only the engagement's parameters, not one that omits findings yet retains other context that invites inference about the test's outcome.

  • A copy of the technical findings with redacted details

    Why it's wrong here

    Redacting exploit details from technical findings is inadequate because document metadata, hidden rows, and visible vulnerability categories or affected-host names can survive in the file and expose sensitive information. Even if the file is clean, the structure of the findings (e.g., severity ratings, affected system names, or vulnerability titles) allows a knowledgeable reader to infer the specific weaknesses that were uncovered. A separate methodology document that never contains findings in the first place is the only clean way to avoid disclosure, as it eliminates the risk of partial redaction and reconstruction.

  • A document describing the testing methodology and scope

    Why this is correct

    A methodology and scope document describes the engagement's rules of engagement, such as the approved testing techniques (e.g., credentialed network scanning, web application testing, social engineering), the target IP ranges and domains, the testing schedule, and the authorization constraints. It contains no vulnerability details, exploit paths, or compromised asset information, making it safe for legal counsel to review for contractual compliance. This document demonstrates that the tester operated within the agreed boundaries while keeping all sensitive findings separate from the legal review package.

  • The remediation plan without the exploit steps

    Why it's wrong here

    A remediation plan is intrinsically vulnerability-centric: it identifies each weakness, its severity rating, and the affected systems so that the IT team can prioritize patching and compensating controls, and it may include references to CVEs or findings IDs even without exploit steps. Legal counsel will view these references as sensitive because they reveal both the existence and the location of exploitable weaknesses within the environment. Therefore, providing the remediation plan—even stripped of attack specifics—fails to give the legal team a clean document that avoids disclosing any vulnerability information.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.