mediumMultiple Select
PT0-002 Practice Question: A penetration tester is preparing a presentation…
A penetration tester is preparing a presentation for both technical and executive audiences. Which TWO of the following are effective strategies for communicating findings to an executive audience?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Focus on business risk and financial impact.
Executives need high-level overviews and business impact, not technical details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Discuss each vulnerability's CVSS vector string.
Why it's wrong here
Discussing each vulnerability's CVSS vector string requires the audience to understand CVSS v3.x metric notation (e.g., AV:N/AC:L/PR:N) and its scoring nuances, which is not practical for executives. The vector string describes exploitability and environmental factors, but it does not translate into monetary loss, downtime, or regulatory impact. Executives need risk expressed in business terms, not raw technical scoring data.
- ✓
Focus on business risk and financial impact.
Why this is correct
Focusing on business risk and financial impact is correct because executives are responsible for risk acceptance, budget allocation, and strategic planning. Presenting findings as likely financial losses, regulatory penalties, or reputational damage connects technical vulnerabilities to the organization's bottom line. This approach enables informed risk management decisions rather than technical discussion.
- ✗
Use technical jargon and detailed exploit steps.
Why it's wrong here
Using technical jargon and detailed exploit steps overwhelms a non-technical executive audience and misses the point of the presentation—to enable resource prioritization. Detailed exploit chains may also reveal sensitive attack methods to unintended audiences, violating the principle of least privilege. The content should be abstracted to attack path, affected assets, and mitigation urgency.
- ✓
Provide a high-level summary with visual aids.
Why this is correct
Providing a high-level summary with visual aids is effective because charts, dashboards, and infographics condense complex data into actionable insights quickly. Visuals help executives grasp severity distributions, affected business units, and trend data without reading technical reports. This approach respects their limited time and improves message retention.
- ✗
Include raw command-line output in slides.
Why it's wrong here
Including raw command-line output in slides is inappropriate because output like nmap scans or Metasploit sessions is unintelligible to executives and adds noise rather than clarity. Such artifacts should be placed in appendices for technical stakeholders. The main presentation should synthesize this data into plain-language impacts and recommendations.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.