Courseiva
easyMultiple Choice

PT0-002 Practice Question: After completing a penetration test, the client's…

After completing a penetration test, the client's technical team requests a detailed list of all vulnerabilities found, prioritized by severity, along with step-by-step reproduction steps and remediation guidance. In which section of the standard penetration testing report should this information be provided?

⚠ Common exam trap

Many candidates confuse the Executive Summary's high-level risk overview with the detailed technical breakdown required by the client's technical team, leading them to choose Option A instead of the Findings section.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Findings

The Findings section of a standard penetration testing report is the correct location for a detailed, prioritized list of vulnerabilities with step-by-step reproduction steps and remediation guidance. This section provides the technical depth required by the client's technical team, contrasting with the high-level summaries found elsewhere.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Executive Summary

    Why it's wrong here

    The Executive Summary is written for non-technical management and business stakeholders, providing a high-level overview of the engagement's objectives, overall risk posture, and strategic recommendations. It deliberately omits step-by-step technical details, such as exact exploit commands or vulnerability reproduction steps, because those readers require brevity and business impact rather than actionable technical depth. A technical team seeking to patch or verify issues would find this section insufficient, as it summarizes rather than specifies.

  • ✗

    Methodology

    Why it's wrong here

    The Methodology section documents the penetration testing process itself, including the scope, rules of engagement, tools used, and phases such as reconnaissance, scanning, exploitation, and post-exploitation. Its purpose is to demonstrate how the test was conducted and to justify the validity of the test, not to catalog the specific vulnerabilities that were discovered. While the technical team may use it to understand the context of the test, they would not locate detailed findings here, as those are reserved for the Findings section.

  • ✓

    Findings

    Why this is correct

    The Findings section is the definitive technical record of every discovered vulnerability, listing each issue with its severity rating, affected asset, detailed reproduction steps, proof of concept, and recommended remediation actions. It is structured to give the client's technical team everything they need to re-create the issue, validate the risk, and implement fixes in a prioritized manner. Unlike the executive summary, it is written for practitioners, assuming a deep technical understanding, and it is the primary section referenced during the remediation phase.

  • ✗

    Appendices

    Why it's wrong here

    Appendices serve as a repository for supplementary material, such as raw network scan exports, Nmap output, Burp Suite screenshots, or intercepted traffic captures, that support the findings but are too granular for the main body. While these artifacts can help a technical team corroborate evidence, they lack the contextual narrative and remediation guidance that the Findings section provides. The appendices alone do not explain the impact or fix for a vulnerability; they are reference data, not the primary detailed findings.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.