easyMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration tester is preparing the executive…
A penetration tester is preparing the executive summary of a report for a client's board of directors. Which of the following metrics would be MOST valuable for this audience to understand the overall security posture?
⚠ Common exam trap
Many exam-takers think exact CVSS scores (Option A) are more precise and therefore more valuable, but the board needs actionable risk summaries, not technical precision.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A heat map showing the number of vulnerabilities by severity (Critical, High, Medium, Low)
The board of directors needs a high-level, risk-based overview of the security posture, not technical details. A heat map with vulnerability counts by severity (Critical, High, Medium, Low) provides an immediate visual representation of risk distribution, enabling strategic decisions without requiring technical expertise. This aligns with the PT0-002 objective of tailoring reporting to the audience.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The exact CVSS score for each vulnerability found
Why it's wrong here
Raw CVSS scores are engineered for technical prioritization—the vector string captures attack vector, complexity, and impact, but that level of granularity obscures business risk for executives. A score of 9.8 in a low-value isolated test environment is not the same as a 6.5 on an internet-facing payment server, and executives need that contextualized judgment. The executive summary should present the aggregate risk exposure and recommended actions, not the metric itself.
- ✓
A heat map showing the number of vulnerabilities by severity (Critical, High, Medium, Low)
Why this is correct
A heat map visually encodes severity distribution—typically using color intensity or a matrix with rows like Critical, High, Medium, and Low—so readers can instantly grasp whether the environment is mostly green or dominated by red. It aligns with common executive risk-reporting practices and supports trend comparisons against prior assessments. For non-technical stakeholders, this is far more effective than a table of CVSS vectors because it translates technical severity into a quick, memorable snapshot of the organization's security posture.
- ✗
A detailed list of commands used during exploitation
Why it's wrong here
Exploitation commands are operational evidence—they document the exact attack path taken, which is exactly what technical remediation teams need to recreate and fix the underlying flaws. But in an executive summary, such detail buries the strategic message under tactical noise and can even pose a release risk if the report is shared broadly. The appropriate place is the appendices or technical narrative, not the executive-level overview.
- ✗
The names of the operating systems and applications that were tested
Why it's wrong here
Simply listing tested operating systems and applications reports the scope of the engagement but says nothing about the risk that was found. Executives need to know how many findings were critical, which business assets are exposed, and what the potential impact might be—not just a technology inventory. A bare list also fails to provide any comparative measure of the company's security posture over time or against industry benchmarks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.