easyMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration tester is preparing the executive…
A penetration tester is preparing the executive summary for a report. Which of the following metrics would be MOST valuable to include for non-technical stakeholders to understand the overall security posture?
⚠ Common exam trap
Test-takers frequently choose Option B (total vulnerabilities and average CVSS score) because CVSS is a familiar metric, but the exam tests the understanding that non-technical stakeholders need actionable, prioritized risk data (critical/high count and exploit time) rather than a statistically averaged score that can obscure severe findings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The number of critical and high-risk findings along with the average time to exploit them
Non-technical stakeholders (e.g., executives) need a high-level, risk-focused summary that communicates the severity and urgency of findings. The number of critical/high-risk findings directly indicates the most dangerous exposures, and the average time to exploit them conveys how quickly an attacker could compromise the environment. This metric translates technical risk into business impact, which is the core goal of an executive summary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A list of all tools used during the penetration test
Why it's wrong here
A list of tools used during the penetration test provides operational detail about the testing methodology, but it does not quantify the organisation’s security posture in terms of risk exposure or remediation urgency. Non-technical stakeholders require metrics such as the number of critical vulnerabilities found or the mean time to remediate, not tool names. This option is tempting because tool lists are standard in the technical findings section of a report, where they demonstrate testing rigour to technical readers.
- ✗
The total number of vulnerabilities discovered and their average CVSS score
Why it's wrong here
Reporting only the total vulnerability count and the average CVSS score is misleading for an executive audience, because a large number of low-severity issues will pull the average down and obscure the presence of a few exploitable critical flaws. CVSS base scores are also computed in isolation, ignoring actual exploitability, attack path complexity, or the value of the affected asset. Executives need risk-prioritized metrics—such as counts of critical/high findings and exploit time—not a statistical summary that masks the urgent exposures.
- ✓
The number of critical and high-risk findings along with the average time to exploit them
Why this is correct
The number of critical and high-risk findings, paired with the average time to exploit them, directly conveys the organization's most urgent exposures in a business-relevant way. This metric tells executives how many vulnerabilities pose an immediate threat and how quickly an attacker could leverage them, which is more actionable than raw severity scores. It frames the summary around exposure and remediation urgency, allowing leadership to prioritize resources and track risk reduction.
- ✗
A detailed step-by-step exploitation walkthrough of one critical vulnerability
Why it's wrong here
A detailed step-by-step exploitation walkthrough of a single critical vulnerability is too technical and narrowly focused for an executive summary, which should summarize overall risk posture rather than demonstrate a specific attack chain. Such procedural detail belongs in the technical findings annex for security teams, and circulating exploit steps broadly in the executive section increases the risk of misuse or inappropriate disclosure. The summary should instead aggregate findings and highlight business impact, not narrate the penetration tester's actions.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.