Courseiva
easyMultiple Choice

PT0-002 A penetration tester is finalizing a report Practice Question

A penetration tester is finalizing a report. Which section should include a detailed technical explanation of how each vulnerability was exploited?

⚠ Common exam trap

Many candidates confuse the Methodology section (which describes the overall testing process) with the per-vulnerability exploitation details, leading them to incorrectly select Methodology instead of Findings and Recommendations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Findings and Recommendations

The Findings and Recommendations section is the correct place for detailed technical explanations of how each vulnerability was exploited because it provides the technical audience (e.g., system administrators, developers) with the step-by-step attack chain, including specific commands, payloads, and tools used. This section bridges the gap between raw scan data and actionable remediation, ensuring that the technical team can reproduce and verify the findings. The Executive Summary is too high-level for this detail, and the Methodology section describes the overall approach, not per-vulnerability exploitation steps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Executive Summary

    Why it's wrong here

    The Executive Summary is intentionally written for non-technical stakeholders, such as senior management and executives, to convey the overall security risk and business impact in a clear, non-technical manner. It should summarize the key findings, risk levels, and remediation priorities at a high level, but it deliberately omits step-by-step exploitation details, exact commands, and payloads. Including such technical narratives would conflict with its purpose and may expose sensitive information if the report is distributed outside the immediate remediation team.

  • ✓

    Findings and Recommendations

    Why this is correct

    The Findings and Recommendations section is the technical core of a penetration test report, containing a detailed description of each discovered vulnerability, its risk rating (e.g., CVSS score), affected assets, and a step-by-step proof of concept that demonstrates how the vulnerability was exploited. This is where the tester documents the precise attack chain, from initial vector to final impact, so that the client's technical remediation team can reproduce, verify, and fix the issue. It also pairs each finding with specific mitigation steps, making it the most actionable section for technical personnel.

  • ✗

    Methodology

    Why it's wrong here

    The Methodology section explains the overall testing process, including the phases of the engagement (e.g., reconnaissance, scanning, exploitation, post-exploitation) and the tools used during those phases. It does not focus on any specific vulnerability found; rather, it outlines the approach, scope, and limitations that governed how the test was conducted. While it provides context for the findings, a detailed narrative of how a particular system was compromised belongs in the Findings and Recommendations section, not here.

  • ✗

    Appendix

    Why it's wrong here

    The Appendix serves as a repository for supporting evidence and reference material, such as raw scan outputs, packet captures, script source code, and configuration snippets. These deliverables are supplementary and are meant to back up the claims made in the Findings and Recommendations section, but they do not contain the primary analysis or the synthesized explanation of how an exploit was performed. The main technical details, including the list of vulnerabilities and remediation guidance, are always presented in the Findings and Recommendations section itself.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.