Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration tester is preparing the executive…

A penetration tester is preparing the executive summary of a report for a client's board of directors. Which of the following metrics would be MOST valuable for this audience to understand the overall security posture?

⚠ Common exam trap

Many exam-takers think exact CVSS scores (Option A) are more precise and therefore more valuable, but the board needs actionable risk summaries, not technical precision.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A heat map showing the number of vulnerabilities by severity (Critical, High, Medium, Low)

The board of directors needs a high-level, risk-based overview of the security posture, not technical details. A heat map with vulnerability counts by severity (Critical, High, Medium, Low) provides an immediate visual representation of risk distribution, enabling strategic decisions without requiring technical expertise. This aligns with the PT0-002 objective of tailoring reporting to the audience.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The exact CVSS score for each vulnerability found

    Why it's wrong here

    Raw CVSS scores are engineered for technical prioritization—the vector string captures attack vector, complexity, and impact, but that level of granularity obscures business risk for executives. A score of 9.8 in a low-value isolated test environment is not the same as a 6.5 on an internet-facing payment server, and executives need that contextualized judgment. The executive summary should present the aggregate risk exposure and recommended actions, not the metric itself.

  • A heat map showing the number of vulnerabilities by severity (Critical, High, Medium, Low)

    Why this is correct

    A heat map visually encodes severity distribution—typically using color intensity or a matrix with rows like Critical, High, Medium, and Low—so readers can instantly grasp whether the environment is mostly green or dominated by red. It aligns with common executive risk-reporting practices and supports trend comparisons against prior assessments. For non-technical stakeholders, this is far more effective than a table of CVSS vectors because it translates technical severity into a quick, memorable snapshot of the organization's security posture.

  • A detailed list of commands used during exploitation

    Why it's wrong here

    Exploitation commands are operational evidence—they document the exact attack path taken, which is exactly what technical remediation teams need to recreate and fix the underlying flaws. But in an executive summary, such detail buries the strategic message under tactical noise and can even pose a release risk if the report is shared broadly. The appropriate place is the appendices or technical narrative, not the executive-level overview.

  • The names of the operating systems and applications that were tested

    Why it's wrong here

    Simply listing tested operating systems and applications reports the scope of the engagement but says nothing about the risk that was found. Executives need to know how many findings were critical, which business assets are exposed, and what the potential impact might be—not just a technology inventory. A bare list also fails to provide any comparative measure of the company's security posture over time or against industry benchmarks.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.