Courseiva
mediumMultiple Choice

PT0-002 Practice Question: After completing a penetration test, the tester…

After completing a penetration test, the tester prepares the final report. According to best practices, which of the following should be included in the executive summary?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

High-level findings, risk ratings, and strategic recommendations

The executive summary should provide high-level findings, risk ratings, and strategic recommendations. Option A is wrong because detailed vulnerability lists belong in the technical section. Option B is wrong because exploitation procedures are too detailed. Option C is wrong because personal opinions are unprofessional and subjective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Detailed list of vulnerabilities and CVSS scores

    Why it's wrong here

    A detailed list of vulnerabilities with CVSS scores belongs in the technical findings section, not the executive summary, which must prioritise business impact, risk context, and strategic recommendations for non-technical stakeholders. This option is tempting because CVSS scores provide a standardised severity metric, making them ideal for prioritising remediation in a technical appendix or operational report.

  • ✗

    Step-by-step exploitation procedures

    Why it's wrong here

    Step-by-step exploitation procedures are granular operational details—specific tools, commands, and technical sequences—that do not translate directly into business risk. Executive-level readers are concerned with the likelihood and impact of a compromise, not the method of exploitation. In a well-structured report, this content belongs in a technical appendix for the client's engineering team, and including it in the executive summary could also unintentionally expose sensitive attack techniques to non-cleared personnel.

  • ✗

    The tester's personal opinions about the security posture

    Why it's wrong here

    The tester's personal opinions introduce subjective bias and undermine the credibility and objectivity of the assessment. A professional penetration test report must be evidence-based, citing specific findings, observed behaviors, and measurable risk factors, rather than qualitative impressions. Personal opinions can also create legal and reputational liability if they influence strategic decisions without supporting data, making them inappropriate for an executive summary that is meant to inform and persuade through factual, defensible reasoning.

  • ✓

    High-level findings, risk ratings, and strategic recommendations

    Why this is correct

    High-level findings, risk ratings, and strategic recommendations form the core of an executive summary because they directly address the business impact and remediation priorities that executives care about. Risk ratings, often derived from CVSS or a customized likelihood/impact matrix, condense technical vulnerabilities into a language that non-technical stakeholders can use for resource allocation and risk acceptance. Strategic recommendations provide a roadmap for improving the organization's security posture, linking specific findings to actionable, cost-effective measures that align with the enterprise's risk appetite.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.