Courseiva
mediumMultiple Select

PT0-002 Practice Question: A penetration tester is preparing a presentation…

A penetration tester is preparing a presentation for both technical and executive audiences. Which TWO of the following are effective strategies for communicating findings to an executive audience?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Focus on business risk and financial impact.

Executives need high-level overviews and business impact, not technical details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Discuss each vulnerability's CVSS vector string.

    Why it's wrong here

    Discussing each vulnerability's CVSS vector string requires the audience to understand CVSS v3.x metric notation (e.g., AV:N/AC:L/PR:N) and its scoring nuances, which is not practical for executives. The vector string describes exploitability and environmental factors, but it does not translate into monetary loss, downtime, or regulatory impact. Executives need risk expressed in business terms, not raw technical scoring data.

  • ✓

    Focus on business risk and financial impact.

    Why this is correct

    Focusing on business risk and financial impact is correct because executives are responsible for risk acceptance, budget allocation, and strategic planning. Presenting findings as likely financial losses, regulatory penalties, or reputational damage connects technical vulnerabilities to the organization's bottom line. This approach enables informed risk management decisions rather than technical discussion.

  • ✗

    Use technical jargon and detailed exploit steps.

    Why it's wrong here

    Using technical jargon and detailed exploit steps overwhelms a non-technical executive audience and misses the point of the presentation—to enable resource prioritization. Detailed exploit chains may also reveal sensitive attack methods to unintended audiences, violating the principle of least privilege. The content should be abstracted to attack path, affected assets, and mitigation urgency.

  • ✓

    Provide a high-level summary with visual aids.

    Why this is correct

    Providing a high-level summary with visual aids is effective because charts, dashboards, and infographics condense complex data into actionable insights quickly. Visuals help executives grasp severity distributions, affected business units, and trend data without reading technical reports. This approach respects their limited time and improves message retention.

  • ✗

    Include raw command-line output in slides.

    Why it's wrong here

    Including raw command-line output in slides is inappropriate because output like nmap scans or Metasploit sessions is unintelligible to executives and adds noise rather than clarity. Such artifacts should be placed in appendices for technical stakeholders. The main presentation should synthesize this data into plain-language impacts and recommendations.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.