mediumMultiple Select
PT0-002 Practice Question: A penetration tester is preparing a report that…
A penetration tester is preparing a report that includes technical findings. Which TWO of the following should be included in each technical finding? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remediation steps with code or commands
Each technical finding should include remediation steps and evidence such as screenshots.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Executive summary
Why it's wrong here
The executive summary is a high-level overview of the entire engagement, designed for stakeholders, and it appears once at the front of the report. It is not a per-vulnerability detail; each finding should contain the technical specifics, impact, and remediation for that specific issue. Including a summary of all findings within each finding would be redundant and would obscure the technical detail that clients need for triage.
- ✗
Client's network diagram
Why it's wrong here
A network diagram illustrates the overall environment, including segmentation, hosts, and connections, and is typically included only once in the appendices or a top-level section. Individual findings home in on a particular host or application and do not require a full architectural diagram to be repeated. Reproducing a network diagram for every finding would add unnecessary length to the report and does not help validate or remediate the specific vulnerability.
- ✓
Remediation steps with code or commands
Why this is correct
Each finding must include a clear, actionable remediation plan that gives the client specific commands, code patches, or configuration changes to eliminate the vulnerability. For example, a SQL injection finding should include parameterized query code, and an Apache issue should show the revised configuration directives. This is a core requirement of a professional pentest report because it transforms a security flaw from a technical warning into a practical to-do item.
- ✗
Business impact analysis
Why it's wrong here
Although business impact analysis—assessing potential financial, legal, or reputational damage—is valuable at the overall report level, it is not one of the two specific items that most findings are expected to contain. In-depth impact assessments are usually summarized in the executive summary or a dedicated risk table rather than wrapped into every technical finding. The correct items in this context are the actionable remediation steps and the concrete evidence that proves the vulnerability, both of which are more directly relevant for the client's technical staff.
- ✓
Evidence such as screenshots
Why this is correct
Concrete evidence, such as screenshots, raw command output, or exploit transcripts, is essential for proving that the finding is real and that the vulnerability is exploitable. The evidence should clearly show the attack vector, the resulting impact, and the affected asset, making it easy for the client to reproduce the issue. If a finding lacks evidentiary support, it is essentially an unsubstantiated claim that the client cannot act on with confidence.
Go deeper
Related to this question
Learn chapter
Python for Penetration Testing
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Technical finding
A technical finding is a specific observation or conclusion drawn from analyzing IT systems, logs, or test results that points to a configuration issue, security vulnerability, or operational inefficiency.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.