Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: Provides a non-technical overview for management.

A penetration tester is preparing the final report. The client's CEO wants a high-level overview of the test results, including the overall security posture and business risk, without technical details. Which section of the report should the tester emphasize for the CEO?

⚠ Common exam trap

Many candidates confuse the executive summary with the technical findings section, mistakenly believing the CEO needs detailed vulnerability data to understand risk, when in fact the executive summary is the only section tailored for non-technical decision-makers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Executive summary

The executive summary is the section of a penetration testing report that provides a high-level overview of the test results, focusing on the overall security posture and business risk without technical details. It is specifically designed for non-technical stakeholders like the CEO, who need to understand the impact on the organization without delving into specific vulnerabilities or exploitation steps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Technical findings and recommendations

    Why it's wrong here

    The technical findings and recommendations section is intended for system administrators, engineers, and security staff who will implement fixes. It contains detailed exploit steps, affected hosts and ports, CVSS scores, and sometimes proof-of-concept code. While essential for remediation, this level of technical detail would overwhelm a CEO and obscure the business-level risk. Presenting regulatory or financial impact and strategic priorities is the purpose of a higher-level summary.

  • Executive summary

    Why this is correct

    The executive summary is a concise, non-technical overview placed at the beginning of a penetration test report, specifically addressed to senior leadership. It states the overall risk level, highlights the most important business impacts, and gives high-level recommendations without exposing vulnerability details. This section allows executives to quickly grasp the security posture and decide on resource allocation or prioritization. It is the section most appropriate for a CEO audience.

  • Methodology

    Why it's wrong here

    The methodology section describes the assessment phases—such as reconnaissance, scanning, exploitation, and post-exploitation—and lists the tools and techniques used. It is meant to provide transparency for technical peers or auditors to judge the validity and scope of the test, not to summarize results. Methodology does not translate findings into business risk or revenue impact, making it irrelevant for a CEO-level review. The executive summary, not the methodology, should carry the high-level outcome.

  • Appendices

    Why it's wrong here

    Appendices are supplementary material that contains raw scan data, log extracts, PoC scripts, screenshots, and detailed vulnerability tables. Their purpose is to provide complete supporting evidence that can be scrutinized after the main report is read. Because they are voluminous and highly technical, they are not suitable as the primary source for an executive overview. The executive summary, in contrast, condenses the essential risks and conclusions for a senior audience.

Go deeper

Related to this question

About these practice questions

One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.