easyMultiple Choice
PT0-002 Practice Question: After completing a penetration test, the client's…
After completing a penetration test, the client's board of directors requests a document that provides a high-level overview of the test's objectives, key findings, and business impact. Which section of the standard penetration testing report should be produced for this audience?
⚠ Common exam trap
Many exam-takers confuse the 'Executive Summary' with the 'Technical Findings Section,' thinking the board needs detailed exploit proof-of-concepts, when in fact the board requires only business-level risk context and strategic recommendations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Executive Summary
The executive summary is the section of a penetration testing report designed for non-technical stakeholders, such as the board of directors. It provides a high-level overview of the test's objectives, key findings, and business impact, avoiding technical jargon and focusing on risk and remediation priorities. This aligns with the PT0-002 objective of tailoring communication to the audience.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Executive Summary
Why this is correct
The executive summary is the only report section written specifically for a non-technical audience, such as the board of directors. It condenses the overall risk posture, key findings, and business-impact recommendations into a high-level narrative without relying on exploit details or system-level jargon. This section prioritizes findings by severity and financial/strategic risk, enabling executives to make informed governance decisions without reading the rest of the report.
- ✗
Technical Findings Section
Why it's wrong here
The technical findings section is intended for system administrators, engineers, and other personnel who require full exploitation steps, proof-of-concept commands, and precise remediation instructions. It assumes deep technical knowledge and uses raw data like CVSS scores, CVE identifiers, and network diagrams, which would overwhelm a board of directors. Executives cannot extract the business impact from this section because it focuses on 'how' to fix rather than 'why' it matters strategically, making it inappropriate for governance-level review.
- ✗
Methodology Section
Why it's wrong here
The methodology section documents the penetration test's scope, rules of engagement, tools used, and the phases of testing (reconnaissance, exploitation, post-exploitation, etc.). It provides procedural transparency and confirms the test followed industry standards, but it does not synthesize findings or assign business risk ratings. This section explains what was done and how, yet it leaves the reader without a bottom-line prioritization, so it is not useful for the board's decision-making or resource allocation.
- ✗
Appendix with Logs
Why it's wrong here
Appendices contain raw supporting artifacts such as firewall logs, Burp Suite exports, Nessus scan reports, and full packet captures. These items are unprocessed and require technical expertise to interpret; they serve as forensic evidence for verification and legal retention, not as a communication tool. The volume and granularity of logs obscure the overall risk picture, making this section unsuitable for an executive audience that needs a concise, synthesized view of threats and impacts.
Go deeper
Related to this question
Learn chapter
Burp Suite for Web Application Testing
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.