Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester is writing a report and…

A penetration tester is writing a report and needs to classify vulnerabilities by risk level. The client has a formal risk acceptance process. Which of the following best describes the purpose of including a risk acceptance section in the report?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To record vulnerabilities the client has decided not to fix, with justification

Option B is correct because a risk acceptance section formally records vulnerabilities that the client has consciously chosen not to remediate, along with the business justification and any compensating controls, which aligns with the client's formal risk acceptance process. This section documents the client's informed decision to retain the residual risk rather than fix it. Option A is wrong because remediation instructions belong in the findings/remediation guidance, not the risk acceptance section. Option C is wrong because a tester's decision not to exploit a vulnerability relates to testing scope or methodology, not risk acceptance. Option D is wrong because documenting all vulnerabilities is the purpose of the findings section, not the risk acceptance section.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To provide step-by-step remediation instructions

    Why it's wrong here

    Remediation instructions belong in the findings or recommendations section, not a risk acceptance section, which records the client's decision to tolerate a risk. It is tempting because remediation guidance is a core report deliverable, making it the right content when the question asks how to help the client fix identified vulnerabilities.

  • ✓

    To record vulnerabilities the client has decided not to fix, with justification

    Why this is correct

    The risk acceptance section documents findings the client formally chooses not to remediate, capturing the justification and accepting party. This satisfies their risk acceptance process and protects the tester from liability for known, accepted issues.

  • ✗

    To justify why the tester did not exploit certain vulnerabilities

    Why it's wrong here

    Risk acceptance documents the client's decision to tolerate a finding, not the tester's exploitation choices; exploitation scope is covered in the methodology or findings sections. It is tempting because testers do record why certain exploits were not attempted, which belongs in an approach or limitations section rather than a risk acceptance one.

  • ✗

    To document all vulnerabilities found during the test

    Why it's wrong here

    A full vulnerability inventory belongs in the findings section; the risk acceptance section records only which findings the client formally accepts. It is tempting because complete documentation of every finding is a standard reporting requirement, making that the correct answer when the question asks how to present all discovered vulnerabilities.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.