mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is writing the executive…
A penetration tester is writing the executive summary of a report. Which of the following is MOST important to include?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Overall risk rating and strategic recommendations
The executive summary should provide a high-level overview in business language, including the overall risk rating, key findings, and strategic recommendations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Overall risk rating and strategic recommendations
Why this is correct
The executive summary must communicate the overall risk posture in terms of business impact, not technical minutiae. It should distill the assessment’s highest-level findings into a prioritized risk rating (e.g., Critical, High, Medium) and pair that with strategic recommendations—such as immediate remediation focus areas, resource investments, or process changes—so leadership can make informed decisions. This aligns with the requirement to present the big picture in language that resonates with non-technical executives, who care about likelihood and business damage, not exploit syntax.
- ✗
Step-by-step exploitation commands
Why it's wrong here
Including step-by-step exploitation commands in the executive summary is inappropriate because it shifts the focus from business impact to offensive operational detail. Such commands are intended for the technical findings section (or a separate technical annex) where security engineers can reproduce the exact attack path for verification and remediation. Furthermore, placing them up front risks exposing sensitive exploit procedures to readers who lack the need-to-know, and it distracts from the strategic risk narrative that the executive audience requires.
- ✗
Raw tool output and screenshots
Why it's wrong here
Raw tool output and screenshots are unsynthesized data that lack context, prioritization, and business relevance; they belong in appendices for technical validation, not in the executive summary. Executives do not need to inspect Nmap scan dumps, Metasploit console logs, or individual proof-of-concept screenshots to grasp the security posture. Including such artifacts obscures the key takeaways and can overwhelm the reader, undermining the summary’s purpose of conveying concise, actionable conclusions.
- ✗
Detailed CVSS scores for every vulnerability
Why it's wrong here
Listing detailed CVSS scores for every vulnerability is a technical exercise that bogs down the executive summary with granular numerical data. CVSS scores require interpretation—base, temporal, and environmental metrics, attack vector nuances, and exploitability—which is beyond the scope of an executive briefing. Executives need the aggregated risk picture (e.g., number of critical issues and their aggregate business exposure) rather than a comprehensive score sheet; the exhaustive per-vulnerability scores belong in the technical findings section where remediation teams can act on them.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
Key term
Risk rating
A risk rating is a score or label assigned to a potential security threat or vulnerability that indicates how likely it is to cause harm and how severe that harm would be.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.