easyMultiple Choice
PT0-002 Practice Question: A penetration tester is compiling the final report
A penetration tester is compiling the final report. The client's compliance officer requires a section that maps each finding to specific regulatory requirements (e.g., PCI DSS, HIPAA). Which section of the report is best suited for this mapping?
⚠ Common exam trap
It's easy for candidates to confuse the Technical Findings section as the place for all detailed information, including compliance references, but the exam expects a dedicated Compliance Mapping section to satisfy audit and regulatory requirements separately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance Mapping
The Compliance Mapping section is specifically designed to cross-reference each technical finding with relevant regulatory frameworks such as PCI DSS, HIPAA, or GDPR. This allows the compliance officer to quickly verify that all required controls are addressed and that the report meets audit or legal standards. The other sections focus on summarizing or detailing technical issues, not on mapping findings to specific regulations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Executive Summary
Why it's wrong here
The executive summary provides a high-level overview for senior leadership, focusing on business risk, attack narrative, and overall security posture rather than regulatory specifics. It may reference compliance only in passing, such as noting a general failure to meet PCI DSS or HIPAA objectives, but it lacks the per-finding control IDs, regulatory citations, and audit trail required by a compliance officer. While it communicates urgency and strategic priorities, it does not offer the detailed cross-reference between each vulnerability and a specific compliance clause, making it an inadequate tool for formal compliance mapping.
- ✗
Technical Findings
Why it's wrong here
The technical findings section catalogs each vulnerability with technical detail such as CVSS scores, proof-of-concept commands, affected asset identifiers, and recommended remediation steps. It is organized by severity, attack chain, or asset criticality, not by regulatory framework or control objective, so a compliance officer cannot easily trace which PCI DSS requirements or HIPAA Security Rule provisions are violated. This section serves as the raw input for compliance mapping but does not itself perform the mapping, as it lacks a structured matrix correlating findings to specific regulatory citations and control failures.
- ✓
Compliance Mapping
Why this is correct
The compliance mapping section is purpose-built to translate technical vulnerabilities into a regulatory context, directly addressing the compliance officer's need for a clear correlation. It typically uses a matrix that maps each finding to applicable standards—such as PCI DSS requirements, HIPAA administrative/technical safeguards, or SOC 2 criteria—including the failed control, evidence of non-compliance, and recommended remediation actions. This section provides a direct, defensible audit trail and demonstrates the organization's compliance posture, enabling stakeholders to prioritize remediation based on both technical risk and legal/regulatory obligations.
- ✗
Appendices
Why it's wrong here
Appendices contain supplementary raw data, such as full scan exports, packet captures, authentication test logs, and interviewer notes, which support the report's evidence but are not synthesized into a compliance framework. They are intentionally structured for evidential completeness and reproducibility, not for end-user analysis, so they lack the cross-referenced mapping to regulatory clauses that the compliance officer requires. While an auditor might refer to an appendix to verify a specific finding, the appendices do not contain the consolidated compliance matrix or the interpretive context needed to assess the overall regulatory impact.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.