Courseiva
easyMultiple Choice

PT0-002 Practice Question: After completing a penetration test, the client's…

After completing a penetration test, the client's board of directors requests a document that provides a high-level overview of the test's objectives, key findings, and business impact. Which section of the standard penetration testing report should be produced for this audience?

⚠ Common exam trap

Many exam-takers confuse the 'Executive Summary' with the 'Technical Findings Section,' thinking the board needs detailed exploit proof-of-concepts, when in fact the board requires only business-level risk context and strategic recommendations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Executive Summary

The executive summary is the section of a penetration testing report designed for non-technical stakeholders, such as the board of directors. It provides a high-level overview of the test's objectives, key findings, and business impact, avoiding technical jargon and focusing on risk and remediation priorities. This aligns with the PT0-002 objective of tailoring communication to the audience.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Executive Summary

    Why this is correct

    The executive summary is the only report section written specifically for a non-technical audience, such as the board of directors. It condenses the overall risk posture, key findings, and business-impact recommendations into a high-level narrative without relying on exploit details or system-level jargon. This section prioritizes findings by severity and financial/strategic risk, enabling executives to make informed governance decisions without reading the rest of the report.

  • ✗

    Technical Findings Section

    Why it's wrong here

    The technical findings section is intended for system administrators, engineers, and other personnel who require full exploitation steps, proof-of-concept commands, and precise remediation instructions. It assumes deep technical knowledge and uses raw data like CVSS scores, CVE identifiers, and network diagrams, which would overwhelm a board of directors. Executives cannot extract the business impact from this section because it focuses on 'how' to fix rather than 'why' it matters strategically, making it inappropriate for governance-level review.

  • ✗

    Methodology Section

    Why it's wrong here

    The methodology section documents the penetration test's scope, rules of engagement, tools used, and the phases of testing (reconnaissance, exploitation, post-exploitation, etc.). It provides procedural transparency and confirms the test followed industry standards, but it does not synthesize findings or assign business risk ratings. This section explains what was done and how, yet it leaves the reader without a bottom-line prioritization, so it is not useful for the board's decision-making or resource allocation.

  • ✗

    Appendix with Logs

    Why it's wrong here

    Appendices contain raw supporting artifacts such as firewall logs, Burp Suite exports, Nessus scan reports, and full packet captures. These items are unprocessed and require technical expertise to interpret; they serve as forensic evidence for verification and legal retention, not as a communication tool. The volume and granularity of logs obscure the overall risk picture, making this section unsuitable for an executive audience that needs a concise, synthesized view of threats and impacts.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.