Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is presenting findings to a…

A penetration tester is presenting findings to a mixed audience of executives and technical staff. For the executives, the tester should focus on:

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk ratings, business impact, and high-level remediation strategy

Executives are interested in business risk, impact, and strategic recommendations, not technical details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Raw tool output and log files

    Why it's wrong here

    Raw tool output and log files, such as Nmap scans, Nessus .nessus files, or Burp Suite proxy logs, are verbose, technical, and overloaded with false positives that lack business context. Executives require a distilled, prioritized view of risk, not a data dump that forces them to interpret technical artifacts without domain expertise. Presenting unprocessed output obscures the bottom-line impact and can erode confidence in the assessment's clarity and utility.

  • ✓

    Risk ratings, business impact, and high-level remediation strategy

    Why this is correct

    Risk ratings, business impact, and a high-level remediation strategy align security findings directly with the organization's operational and financial goals, which is what executive audiences need to prioritize actions and allocate resources. Ratings such as Critical/High/Medium/Low, derived from likelihood and impact (e.g., CVSS base scores adjusted for business context), translate technical vulnerabilities into decision-ready language. The high-level remediation strategy—such as 'segment the payment network' or 'accelerate patching of internet-facing systems'—gives executives actionable direction without drowning them in implementation minutiae.

  • ✗

    Detailed exploit code and proof-of-concept

    Why it's wrong here

    Detailed exploit code and proof-of-concept scripts are inappropriate for executives because they are operationally sensitive and technically esoteric; they focus on how a vulnerability is abused rather than the resulting business exposure. Such content is typically reserved for technical staff or developers who need to validate and mitigate the specific weakness, and sharing it widely increases the risk of accidental or malicious misuse. Executives only need to know the severity of the vulnerability and its potential business consequence, not the step-by-step exploitation mechanics.

  • ✗

    Step-by-step remediation commands

    Why it's wrong here

    Step-by-step remediation commands, such as specific firewall ACL changes, registry edits, or configuration snippets, are tactical and environment-specific, meant for system administrators and IT engineers who implement fixes. Executives neither need nor can act on such low-level details; their responsibility is to approve budgets, set policy, and oversee risk management, not to execute shell commands. Overloading an executive presentation with operational commands detracts from strategic decision-making and can make the report feel inaccessible to its primary audience.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.