hardMultiple Choice
PT0-002 Practice Question: A penetration tester is writing a report and…
A penetration tester is writing a report and needs to classify vulnerabilities by risk level. The client has a formal risk acceptance process. Which of the following best describes the purpose of including a risk acceptance section in the report?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To record vulnerabilities the client has decided not to fix, with justification
Option B is correct because a risk acceptance section formally records vulnerabilities that the client has consciously chosen not to remediate, along with the business justification and any compensating controls, which aligns with the client's formal risk acceptance process. This section documents the client's informed decision to retain the residual risk rather than fix it. Option A is wrong because remediation instructions belong in the findings/remediation guidance, not the risk acceptance section. Option C is wrong because a tester's decision not to exploit a vulnerability relates to testing scope or methodology, not risk acceptance. Option D is wrong because documenting all vulnerabilities is the purpose of the findings section, not the risk acceptance section.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To provide step-by-step remediation instructions
Why it's wrong here
Remediation instructions belong in the findings or recommendations section, not a risk acceptance section, which records the client's decision to tolerate a risk. It is tempting because remediation guidance is a core report deliverable, making it the right content when the question asks how to help the client fix identified vulnerabilities.
- ✓
To record vulnerabilities the client has decided not to fix, with justification
Why this is correct
The risk acceptance section documents findings the client formally chooses not to remediate, capturing the justification and accepting party. This satisfies their risk acceptance process and protects the tester from liability for known, accepted issues.
- ✗
To justify why the tester did not exploit certain vulnerabilities
Why it's wrong here
Risk acceptance documents the client's decision to tolerate a finding, not the tester's exploitation choices; exploitation scope is covered in the methodology or findings sections. It is tempting because testers do record why certain exploits were not attempted, which belongs in an approach or limitations section rather than a risk acceptance one.
- ✗
To document all vulnerabilities found during the test
Why it's wrong here
A full vulnerability inventory belongs in the findings section; the risk acceptance section records only which findings the client formally accepts. It is tempting because complete documentation of every finding is a standard reporting requirement, making that the correct answer when the question asks how to present all discovered vulnerabilities.
Go deeper
Related to this question
Learn chapter
Phishing Campaigns in Penetration Testing
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.