Courseiva
mediumMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration tester is preparing a report for a…

A penetration tester is preparing a report for a client that includes both a technical security team and an executive leadership team. The executive team needs to understand the overall risk posture, while the technical team requires detailed reproduction steps. Which reporting structure best serves both audiences?

⚠ Common exam trap

Many exam-takers think separate reports are more 'professional' or 'targeted,' but the PT0-002 exam expects a single cohesive report with layered detail to ensure consistency and traceability between the executive summary and technical findings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A single report with an executive summary and technical appendices

A single report with an executive summary and technical appendices is the correct structure because it satisfies both audiences: the executive summary provides a high-level risk posture overview (e.g., CVSS scores, business impact), while the technical appendices contain detailed reproduction steps (e.g., exact commands, payloads, and packet captures) for the technical team. This approach aligns with the PT0-002 objective of tailoring communication to stakeholders without losing technical rigor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A single report with an executive summary and technical appendices

    Why this is correct

    A single report with an executive summary and technical appendices is the industry-standard structure because it creates a single source of truth while serving both audiences. The executive summary translates technical vulnerabilities into business risk terms, enabling leadership to prioritize remediation, while the technical appendices contain the raw findings, request/response data, reproduction steps, and CVSS scores that security engineers need to validate and fix issues. This format eliminates the risk of version mismatch between separate documents and ensures regulatory or compliance reviewers can trace a high-level risk statement directly to its concrete technical evidence.

  • Two completely separate reports: one for executives and one for technical staff

    Why it's wrong here

    Producing two entirely separate reports prevents the executive team from seeing the technical reproduction steps that justify the risk ratings, and denies the technical team the executive summary that contextualises business impact. This fragmentation forces each audience to cross-reference missing sections, defeating the single-source-of-truth requirement. It is tempting because separate reports allow tailored language and depth for each group, and would be correct if the client mandated strict information segregation to prevent technical details from reaching non-technical readers.

  • Only an executive summary, omitting technical details

    Why it's wrong here

    Delivering only an executive summary omits technical details entirely, which is a severe reporting failure because the technical team cannot reproduce, validate, or remediate the vulnerabilities without specific endpoints, payloads, and evidence. Risk ratings in the executive summary would appear as unsubstantiated claims, and the client would lack the artifacts needed to perform a proper verification of the penetration test's scope and findings. Industry frameworks like PTES require both an executive and a technical section, so this option does not meet minimum reporting expectations.

  • Only a technical report with all details

    Why it's wrong here

    Submitting only a technical report with all details fails the executive audience because system administrators and security engineers are not the sole decision-makers; leadership requires a clear, jargon-free articulation of business impact, such as regulatory exposure, potential financial loss, and impacts on reputation. A raw technical dump forces executives to interpret exploit chains and CVSS vectors themselves, which is unrealistic and can lead to misprioritized remediation budgets. Furthermore, without an executive summary, the report does not communicate the overall security posture in a way that supports board-level governance and strategic risk acceptance.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.