mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is writing the executive…
A penetration tester is writing the executive summary for a report. The client's CEO needs to understand the business impact of a critical SQL injection vulnerability. Which of the following should the tester include?
⚠ Common exam trap
Watch out — candidates often confuse the purpose of an executive summary with a technical report, choosing detailed technical data (payload or CVSS) instead of business impact, which is what the CEO actually needs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The potential for data breach and financial loss
The CEO needs to understand the business impact, not technical details. Option C directly addresses the core concern: a SQL injection vulnerability can lead to unauthorized data access, resulting in a data breach and significant financial loss from fines, remediation costs, and reputational damage. This aligns with the executive summary's goal of translating technical risk into business risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The exact SQL injection payload used
Why it's wrong here
Including the exact SQL injection payload in an executive summary conflates exploit mechanics with business risk. Executives need to understand the potential impact on operations or revenue, not the raw attack syntax. This level of detail belongs in the technical findings section, where remediation engineers can act on it, and it also risks exposing sensitive exploit information to non-essential readers.
- ✗
The CVSS vector string
Why it's wrong here
While the CVSS vector string provides a standardized severity score, it is a technical measure that conveys little actionable meaning to a chief executive. Numbers like 8.1 do not translate directly into dollars, regulatory penalties, or reputational harm. The executive summary should interpret the vulnerability's business context, leaving raw scores for the technical report's risk metric tables.
- ✓
The potential for data breach and financial loss
Why this is correct
The potential for data breach and financial loss directly addresses the business impact that drives executive decision-making. This option frames the vulnerability in terms of material consequences, such as compliance fines, litigation, and customer turnover, which are the primary concerns for leadership. It aligns the summary's content with the audience's strategic perspective, making the risk tangible and actionable at the board level.
- ✗
The remediation steps in detail
Why it's wrong here
Detailed remediation steps, such as specific patch versions or code fixes, are operational guidance that belongs in the findings or technical remediation sections of the report. Executives require a high-level understanding of necessary actions, not step-by-step instructions, to allocate resources and approve budgets. Overloading the executive summary with technical minutiae dilutes the key risk messages and complicates the decision-making process.
Go deeper
Related to this question
Learn chapter
Third-Party and Supply Chain Risk in Scope
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.