mediumMultiple Choice
PT0-002 Practice Question: After completing a penetration test, the tester…
After completing a penetration test, the tester prepares the final report. According to best practices, which of the following should be included in the executive summary?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
High-level findings, risk ratings, and strategic recommendations
The executive summary should provide high-level findings, risk ratings, and strategic recommendations. Option A is wrong because detailed vulnerability lists belong in the technical section. Option B is wrong because exploitation procedures are too detailed. Option C is wrong because personal opinions are unprofessional and subjective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detailed list of vulnerabilities and CVSS scores
Why it's wrong here
A detailed list of vulnerabilities with CVSS scores belongs in the technical findings section, not the executive summary, which must prioritise business impact, risk context, and strategic recommendations for non-technical stakeholders. This option is tempting because CVSS scores provide a standardised severity metric, making them ideal for prioritising remediation in a technical appendix or operational report.
- ✗
Step-by-step exploitation procedures
Why it's wrong here
Step-by-step exploitation procedures are granular operational details—specific tools, commands, and technical sequences—that do not translate directly into business risk. Executive-level readers are concerned with the likelihood and impact of a compromise, not the method of exploitation. In a well-structured report, this content belongs in a technical appendix for the client's engineering team, and including it in the executive summary could also unintentionally expose sensitive attack techniques to non-cleared personnel.
- ✗
The tester's personal opinions about the security posture
Why it's wrong here
The tester's personal opinions introduce subjective bias and undermine the credibility and objectivity of the assessment. A professional penetration test report must be evidence-based, citing specific findings, observed behaviors, and measurable risk factors, rather than qualitative impressions. Personal opinions can also create legal and reputational liability if they influence strategic decisions without supporting data, making them inappropriate for an executive summary that is meant to inform and persuade through factual, defensible reasoning.
- ✓
High-level findings, risk ratings, and strategic recommendations
Why this is correct
High-level findings, risk ratings, and strategic recommendations form the core of an executive summary because they directly address the business impact and remediation priorities that executives care about. Risk ratings, often derived from CVSS or a customized likelihood/impact matrix, condense technical vulnerabilities into a language that non-technical stakeholders can use for resource allocation and risk acceptance. Strategic recommendations provide a roadmap for improving the organization's security posture, linking specific findings to actionable, cost-effective measures that align with the enterprise's risk appetite.
Go deeper
Related to this question
Learn chapter
Python for Penetration Testing
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.