mediumMultiple Select
PT0-002 Practice Question: A penetration tester is preparing the executive…
A penetration tester is preparing the executive summary. Which THREE elements should be included? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Key findings summary
Executive summary should include overall risk rating, key findings, and strategic recommendations. Technical details and methodology are not appropriate for this section.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Key findings summary
Why this is correct
The executive summary is intended for executives and stakeholders who need a concise, non-technical overview of the assessment's most critical outcomes. A key findings summary distills the most impactful vulnerabilities, their potential business impact, and overall security posture into a format that supports rapid understanding and decision-making. It highlights issues requiring immediate executive attention without overwhelming the audience with technical jargon or exhaustive detail.
- ✗
Detailed exploit steps for each vulnerability
Why it's wrong here
While detailed exploit steps are essential for the technical report and remediation teams, they are inappropriate for an executive summary. Executives are not interested in the specific command-line sequences, proof-of-concept code, or step-by-step exploitation chain; they need the bottom-line business risk and recommended actions. Including such granular technical content can also raise security concerns if the report is widely distributed, and it detracts from the high-level focus required at the executive level.
- ✓
Strategic recommendations
Why this is correct
Strategic recommendations translate technical vulnerabilities into actionable, business-aligned guidance that executives can use to prioritize investments, adjust policies, or accept risk. Unlike a summary of findings, which describes what is wrong, recommendations focus on what to do next, linking remediation efforts to business objectives and resource allocation. This is a crucial element of an executive summary because it empowers leadership to make informed decisions about mitigation strategies and long-term security improvements.
- ✓
Overall risk rating
Why this is correct
An overall risk rating provides a single, aggregated metric—such as High, Medium, or Low—that encapsulates the organization's security risk level for executives who lack time to parse individual vulnerabilities. This high-level assessment enables quick comparisons against industry benchmarks, previous assessments, or risk tolerances, and it communicates urgency effectively. It complements the key findings by offering a concise, memorable takeaway that reinforces the severity of the situation without requiring technical explanation.
- ✗
Description of the testing methodology
Why it's wrong here
A detailed description of the testing methodology, including tools used, scanning parameters, and test cases, is too lengthy and procedurally dense for an executive summary. Executives are primarily concerned with results, business impact, and recommendations; however, a brief acknowledgement of methodology may be acceptable. The full methodology should be placed in an appendix or separate section to allow technical staff to verify the assessment's reliability and reproducibility, while keeping the executive summary focused on actionable insights.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Risk rating
A risk rating is a score or label assigned to a potential security threat or vulnerability that indicates how likely it is to cause harm and how severe that harm would be.
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.