Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration tester is preparing the executive…

A penetration tester is preparing the executive summary for a report. Which of the following metrics would be MOST valuable to include for non-technical stakeholders to understand the overall security posture?

⚠ Common exam trap

Test-takers frequently choose Option B (total vulnerabilities and average CVSS score) because CVSS is a familiar metric, but the exam tests the understanding that non-technical stakeholders need actionable, prioritized risk data (critical/high count and exploit time) rather than a statistically averaged score that can obscure severe findings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The number of critical and high-risk findings along with the average time to exploit them

Non-technical stakeholders (e.g., executives) need a high-level, risk-focused summary that communicates the severity and urgency of findings. The number of critical/high-risk findings directly indicates the most dangerous exposures, and the average time to exploit them conveys how quickly an attacker could compromise the environment. This metric translates technical risk into business impact, which is the core goal of an executive summary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A list of all tools used during the penetration test

    Why it's wrong here

    A list of tools used during the penetration test provides operational detail about the testing methodology, but it does not quantify the organisation’s security posture in terms of risk exposure or remediation urgency. Non-technical stakeholders require metrics such as the number of critical vulnerabilities found or the mean time to remediate, not tool names. This option is tempting because tool lists are standard in the technical findings section of a report, where they demonstrate testing rigour to technical readers.

  • The total number of vulnerabilities discovered and their average CVSS score

    Why it's wrong here

    Reporting only the total vulnerability count and the average CVSS score is misleading for an executive audience, because a large number of low-severity issues will pull the average down and obscure the presence of a few exploitable critical flaws. CVSS base scores are also computed in isolation, ignoring actual exploitability, attack path complexity, or the value of the affected asset. Executives need risk-prioritized metrics—such as counts of critical/high findings and exploit time—not a statistical summary that masks the urgent exposures.

  • The number of critical and high-risk findings along with the average time to exploit them

    Why this is correct

    The number of critical and high-risk findings, paired with the average time to exploit them, directly conveys the organization's most urgent exposures in a business-relevant way. This metric tells executives how many vulnerabilities pose an immediate threat and how quickly an attacker could leverage them, which is more actionable than raw severity scores. It frames the summary around exposure and remediation urgency, allowing leadership to prioritize resources and track risk reduction.

  • A detailed step-by-step exploitation walkthrough of one critical vulnerability

    Why it's wrong here

    A detailed step-by-step exploitation walkthrough of a single critical vulnerability is too technical and narrowly focused for an executive summary, which should summarize overall risk posture rather than demonstrate a specific attack chain. Such procedural detail belongs in the technical findings annex for security teams, and circulating exploit steps broadly in the executive section increases the risk of misuse or inappropriate disclosure. The summary should instead aggregate findings and highlight business impact, not narrate the penetration tester's actions.

About these practice questions

This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.