Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester needs to communicate the…

A penetration tester needs to communicate the financial impact of a critical vulnerability to the board of directors. Which metric is most appropriate for this audience?

⚠ Common exam trap

Candidates often choose CVSS score or risk rating because they are familiar from technical reports, but the question specifically asks for a metric to communicate financial impact to the board, which requires a quantitative financial measure like ALE.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Annualized loss expectancy (ALE).

The board of directors is concerned with financial risk and business impact, not technical severity. Annualized loss expectancy (ALE) quantifies the expected monetary loss per year from a vulnerability, making it directly relevant for executive decision-making. CVSS scores and risk ratings are technical metrics that do not translate to financial terms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CVSS base score (e.g., 9.8 out of 10).

    Why it's wrong here

    CVSS base scores such as 9.8 rank the technical severity of a vulnerability based on exploitability and impact on confidentiality, integrity, and availability. However, CVSS does not incorporate asset value, business criticality, or any monetary dimension, so it cannot express the financial impact that executives need to justify security spending or compare against other enterprise risks.

  • ✗

    Risk rating (High, Medium, Low).

    Why it's wrong here

    Qualitative risk ratings like High, Medium, or Low aggregate likelihood and impact using ordinal labels, but they lack the granularity needed for financial decision-making. Two risks both rated “High” can differ by orders of magnitude in potential dollar loss, making it impossible for board members to prioritize investments or determine whether a $500,000 mitigation is justified. ALE provides a more precise monetary basis.

  • ✓

    Annualized loss expectancy (ALE).

    Why this is correct

    Annualized loss expectancy (ALE) is the product of single loss expectancy (SLE) and annualized rate of occurrence (ARO), expressed as a dollar figure per year. This directly quantifies the expected financial impact from a risk, allowing executives to compare it with potential countermeasure costs and other business investments. ALE is the standard metric for translating technical risk into business language, enabling cost-benefit analysis of risk mitigation options.

  • ✗

    Number of affected systems.

    Why it's wrong here

    The number of affected systems is a purely technical inventory count that omits critical variables such as data value, system role, potential regulatory fines, and recovery costs. A single server containing thousands of customer PII records can have a financial impact far exceeding hundreds of low-value, non-sensitive endpoints. Financial impact assessments must consider loss magnitude, not just the breadth of the exposed environment.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.