PT0-002 Engagement Management Practice Question
A penetration tester is preparing a deliverable for a client. Which of the following should be included in the final report?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Executive summary, technical findings, and remediation guidance
A standard penetration testing report includes an executive summary, technical findings, and remediation guidance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Executive summary, technical findings, and remediation guidance
Why this is correct
The standard penetration test deliverable comprises an executive summary for non-technical stakeholders, detailed technical findings for security engineers, and remediation guidance to address identified vulnerabilities. This structure ensures every audience—from management to IT—receives actionable information tailored to their role. It aligns with industry best practices such as the PTES report format and enables the client to prioritize and fix issues effectively.
- ✗
The tester's personal notes and observations
Why it's wrong here
The tester's personal notes and observations are informal, unstructured, and may contain assumptions, hunches, or partially verified information that was not intended for client review. Including them in a formal report could expose raw testing methodology, unvalidated false positives, or sensitive data, damaging credibility and potentially breaching confidentiality. Professional deliverables require a curated, evidence-based narrative, not a stream-of-consciousness log.
- ✗
Only the technical findings
Why it's wrong here
A report containing only technical findings gives engineers the raw vulnerabilities and proof-of-concept details but omits the executive summary that translates risk into business impact and the remediation guidance needed to fix the issues. Without prioritization or context, management cannot assess organizational exposure, and IT staff are left without clear, actionable next steps. This incomplete format fails the client's need for both strategic and tactical direction.
- ✗
Only the executive summary
Why it's wrong here
An executive summary alone provides a high-level risk overview and metrics, but it lacks the technical evidence, reproduction steps, and detailed remediation instructions that engineers require to validate and resolve each vulnerability. It may highlight risk trends, but without the underlying technical details, the client's security team cannot act on the findings. The report would be frustratingly vague for the technical audience, undermining its usefulness as a decision-support and action document.
Go deeper
Related to this question
Learn chapter
Physical Security Testing Techniques
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.