Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is writing the executive…

A penetration tester is writing the executive summary of a report. Which of the following is MOST important to include?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Overall risk rating and strategic recommendations

The executive summary should provide a high-level overview in business language, including the overall risk rating, key findings, and strategic recommendations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Overall risk rating and strategic recommendations

    Why this is correct

    The executive summary must communicate the overall risk posture in terms of business impact, not technical minutiae. It should distill the assessment’s highest-level findings into a prioritized risk rating (e.g., Critical, High, Medium) and pair that with strategic recommendations—such as immediate remediation focus areas, resource investments, or process changes—so leadership can make informed decisions. This aligns with the requirement to present the big picture in language that resonates with non-technical executives, who care about likelihood and business damage, not exploit syntax.

  • ✗

    Step-by-step exploitation commands

    Why it's wrong here

    Including step-by-step exploitation commands in the executive summary is inappropriate because it shifts the focus from business impact to offensive operational detail. Such commands are intended for the technical findings section (or a separate technical annex) where security engineers can reproduce the exact attack path for verification and remediation. Furthermore, placing them up front risks exposing sensitive exploit procedures to readers who lack the need-to-know, and it distracts from the strategic risk narrative that the executive audience requires.

  • ✗

    Raw tool output and screenshots

    Why it's wrong here

    Raw tool output and screenshots are unsynthesized data that lack context, prioritization, and business relevance; they belong in appendices for technical validation, not in the executive summary. Executives do not need to inspect Nmap scan dumps, Metasploit console logs, or individual proof-of-concept screenshots to grasp the security posture. Including such artifacts obscures the key takeaways and can overwhelm the reader, undermining the summary’s purpose of conveying concise, actionable conclusions.

  • ✗

    Detailed CVSS scores for every vulnerability

    Why it's wrong here

    Listing detailed CVSS scores for every vulnerability is a technical exercise that bogs down the executive summary with granular numerical data. CVSS scores require interpretation—base, temporal, and environmental metrics, attack vector nuances, and exploitability—which is beyond the scope of an executive briefing. Executives need the aggregated risk picture (e.g., number of critical issues and their aggregate business exposure) rather than a comprehensive score sheet; the exhaustive per-vulnerability scores belong in the technical findings section where remediation teams can act on them.

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.