easyMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration tester is preparing a report for a…
A penetration tester is preparing a report for a client who has both a technical security team and a non-technical executive team. The tester wants to ensure that each audience receives the appropriate level of detail. Which of the following is the most effective approach?
⚠ Common exam trap
Many exam-takers choose Option C, thinking two separate reports are more precise, but the exam emphasizes efficiency and consistency, where a single report with both sections avoids redundancy and ensures all stakeholders share the same foundational information.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a single report that includes an executive summary at the beginning and a detailed technical section later.
It provides a single report with an executive summary for non-technical stakeholders and a detailed technical section for the security team, satisfying both audiences' needs without duplication or omission. This approach aligns with industry best practices for penetration testing reporting, as outlined in standards like PTES and NIST SP 800-115, ensuring clear communication of risks and technical findings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Provide the same comprehensive report to both audiences, assuming the security team will interpret it for executives.
Why it's wrong here
Providing the identical comprehensive report to both audiences fails because it mixes raw exploit details, code snippets, and low-level evidence with high-level business risk in a single unstructured narrative. Executives do not need to know the nuances of a SQL injection payload; they need the likelihood and business impact of a data breach. This approach forces the security team to act as an intermediary interpreter, introducing delays and potential miscommunication, and it also exposes sensitive technical details to readers who may not have the proper security clearance or need-to-know, complicating the report's distribution and confidentiality.
- ✓
Create a single report that includes an executive summary at the beginning and a detailed technical section later.
Why this is correct
This is the correct structure because it aligns with standard penetration testing report formats (e.g., PTES, NIST SP 800-115) that use a layered approach. An executive summary at the front provides a concise, non-technical overview of the highest-risk findings, business impact, and strategic recommendations, allowing executives to make informed decisions without reading every command or log. The detailed technical section later includes reproducible vulnerabilities, affected assets, proof-of-concept evidence, CVSS scores, and specific remediation steps, giving the technical staff the exact data they need to verify and fix the issues while preserving a single authoritative document that ties business context to technical reality.
- ✗
Write two separate reports: one for executives with only business impact and another for technical staff with all details.
Why it's wrong here
Writing separate reports isolates business impact from technical detail, but the stem requires a single report that layers information for both audiences—such as an executive summary with technical appendices—so the technical team cannot cross-reference the tester’s findings against the business context. This approach is tempting because it mirrors standard practice for highly sensitive or legally privileged engagements where strict audience segregation is mandated, and it would be correct if the client explicitly forbade sharing technical details with executives.
- ✗
Present only the executive summary and invite the technical team to ask questions orally.
Why it's wrong here
Presenting only the executive summary and handling technical details orally is inadequate because it violates the principle of written evidence and auditability. Technical staff need a permanent, searchable record of reproduction steps, affected endpoints, and tool-specific output to independently verify each vulnerability and track remediation progress; verbal explanations cannot be reviewed, documented, or used as compliance evidence. Additionally, oral communication is ephemeral and error-prone, and the report itself must serve as the official deliverable for the engagement. Without a written technical section, the client cannot formally close out findings, and the pentest may not meet contractual or regulatory reporting requirements.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.