Courseiva
Engagement Management →easyMultiple Choice

PT0-002 Engagement Management Practice Question

A penetration tester is preparing a deliverable for a client. Which of the following should be included in the final report?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Executive summary, technical findings, and remediation guidance

A standard penetration testing report includes an executive summary, technical findings, and remediation guidance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Executive summary, technical findings, and remediation guidance

    Why this is correct

    The standard penetration test deliverable comprises an executive summary for non-technical stakeholders, detailed technical findings for security engineers, and remediation guidance to address identified vulnerabilities. This structure ensures every audience—from management to IT—receives actionable information tailored to their role. It aligns with industry best practices such as the PTES report format and enables the client to prioritize and fix issues effectively.

  • ✗

    The tester's personal notes and observations

    Why it's wrong here

    The tester's personal notes and observations are informal, unstructured, and may contain assumptions, hunches, or partially verified information that was not intended for client review. Including them in a formal report could expose raw testing methodology, unvalidated false positives, or sensitive data, damaging credibility and potentially breaching confidentiality. Professional deliverables require a curated, evidence-based narrative, not a stream-of-consciousness log.

  • ✗

    Only the technical findings

    Why it's wrong here

    A report containing only technical findings gives engineers the raw vulnerabilities and proof-of-concept details but omits the executive summary that translates risk into business impact and the remediation guidance needed to fix the issues. Without prioritization or context, management cannot assess organizational exposure, and IT staff are left without clear, actionable next steps. This incomplete format fails the client's need for both strategic and tactical direction.

  • ✗

    Only the executive summary

    Why it's wrong here

    An executive summary alone provides a high-level risk overview and metrics, but it lacks the technical evidence, reproduction steps, and detailed remediation instructions that engineers require to validate and resolve each vulnerability. It may highlight risk trends, but without the underlying technical details, the client's security team cannot act on the findings. The report would be frustratingly vague for the technical audience, undermining its usefulness as a decision-support and action document.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.