easyMultiple Choice
PT0-002 A penetration tester is finalizing a report Practice Question
A penetration tester is finalizing a report. Which section should include a detailed technical explanation of how each vulnerability was exploited?
⚠ Common exam trap
Many candidates confuse the Methodology section (which describes the overall testing process) with the per-vulnerability exploitation details, leading them to incorrectly select Methodology instead of Findings and Recommendations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Findings and Recommendations
The Findings and Recommendations section is the correct place for detailed technical explanations of how each vulnerability was exploited because it provides the technical audience (e.g., system administrators, developers) with the step-by-step attack chain, including specific commands, payloads, and tools used. This section bridges the gap between raw scan data and actionable remediation, ensuring that the technical team can reproduce and verify the findings. The Executive Summary is too high-level for this detail, and the Methodology section describes the overall approach, not per-vulnerability exploitation steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Executive Summary
Why it's wrong here
The Executive Summary is intentionally written for non-technical stakeholders, such as senior management and executives, to convey the overall security risk and business impact in a clear, non-technical manner. It should summarize the key findings, risk levels, and remediation priorities at a high level, but it deliberately omits step-by-step exploitation details, exact commands, and payloads. Including such technical narratives would conflict with its purpose and may expose sensitive information if the report is distributed outside the immediate remediation team.
- ✓
Findings and Recommendations
Why this is correct
The Findings and Recommendations section is the technical core of a penetration test report, containing a detailed description of each discovered vulnerability, its risk rating (e.g., CVSS score), affected assets, and a step-by-step proof of concept that demonstrates how the vulnerability was exploited. This is where the tester documents the precise attack chain, from initial vector to final impact, so that the client's technical remediation team can reproduce, verify, and fix the issue. It also pairs each finding with specific mitigation steps, making it the most actionable section for technical personnel.
- ✗
Methodology
Why it's wrong here
The Methodology section explains the overall testing process, including the phases of the engagement (e.g., reconnaissance, scanning, exploitation, post-exploitation) and the tools used during those phases. It does not focus on any specific vulnerability found; rather, it outlines the approach, scope, and limitations that governed how the test was conducted. While it provides context for the findings, a detailed narrative of how a particular system was compromised belongs in the Findings and Recommendations section, not here.
- ✗
Appendix
Why it's wrong here
The Appendix serves as a repository for supporting evidence and reference material, such as raw scan outputs, packet captures, script source code, and configuration snippets. These deliverables are supplementary and are meant to back up the claims made in the Findings and Recommendations section, but they do not contain the primary analysis or the synthesized explanation of how an exploit was performed. The main technical details, including the list of vulnerabilities and remediation guidance, are always presented in the Findings and Recommendations section itself.
Go deeper
Related to this question
Learn chapter
Red Team Exercises vs Penetration Tests
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.