Courseiva
mediumMultiple ChoiceObjective-mapped

PT0-002 Practice Question: After a penetration test, the client's…

After a penetration test, the client's development team requires detailed, step-by-step instructions to reproduce a SQL injection vulnerability found in the user login functionality. In which section of the standard penetration testing report should this information be included?

⚠ Common exam trap

Watch out — candidates often confuse the purpose of the Recommendations section, thinking it should include step-by-step reproduction steps, when in fact it only contains high-level remediation guidance, while the Technical Findings section is the proper place for detailed exploitation procedures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Technical Findings

The Technical Findings section is the correct location because it provides detailed, step-by-step reproduction steps for vulnerabilities, including the exact SQL injection payloads, input fields, and HTTP request parameters used to exploit the login functionality. This section is intended for technical audiences (e.g., developers) who need to understand and remediate the issue, not for high-level summaries or general advice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Executive Summary

    Why it's wrong here

    The Executive Summary is tailored for management and non-technical stakeholders, offering a concise overview of the engagement's outcomes, business risks, and strategic priorities. It deliberately omits the granular, step-by-step reproduction instructions that a development team would need. Therefore, it cannot serve as the source for verifying or fixing the vulnerability details.

  • Technical Findings

    Why this is correct

    Technical Findings is the section that provides the exhaustive vulnerability catalogue, including affected endpoints, exact reproduction steps, proof-of-concept commands, and observed technical impact. This is precisely what a development team requires to independently recreate and understand the flaw before implementing a fix. It is written for a technical audience and is the standard location for disclosure of exploit mechanics.

  • Recommendations

    Why it's wrong here

    Recommendations focus on remediation strategies, such as patch versions, configuration changes, or secure coding practices, rather than explaining how to trigger the vulnerability. They assume the reader already knows the vulnerability's location and characteristics from the findings, so they omit the explicit reproduction procedure. A development team cannot use this section alone to verify the vulnerability exists.

  • Risk Rating

    Why it's wrong here

    Risk Rating assigns a severity metric, often via CVSS, that communicates exploitability and business impact in a single score. This score is useful for prioritization but contains no narrative or technical detail about the actual attack path or payloads. It lacks the specific commands or steps needed to reproduce the vulnerability, making it insufficient for the development team's requirements.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.