easyMultiple Choice
Tailoring PenTest Report Findings to Different Stakeholders
During a penetration test, the tester discovers a critical vulnerability that could lead to a data breach. The tester needs to communicate this to the client's management, who are non-technical. What is the BEST way to communicate this finding?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
High-level summary with business impact and recommended timeline for fix
Communicating a critical vulnerability to non-technical management requires translating the technical finding into business terms, so a high-level summary that states the business impact (e.g., potential data breach, regulatory exposure, financial loss) plus a recommended remediation timeline gives executives what they need to prioritize and authorize action. This approach aligns with standard penetration-test reporting practices such as those in PTES, where executive summaries convey risk and urgency without technical jargon. Option A fails because burying a critical finding only in the final report delays awareness and response. Option C is inadequate because an 'URGENT' email with no details provides no context for decision-making. Option D is inappropriate for a non-technical audience since detailed exploit steps belong in the technical section of the report, not in management communication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include the finding only in the final report
Why it's wrong here
Deferring a critical, breach-capable finding to the final report delays management awareness until remediation windows have passed. Reports suit complete documentation of all findings. A critical issue requires immediate interim communication, with the report serving as the formal record afterwards.
- ✓
High-level summary with business impact and recommended timeline for fix
Why this is correct
Non-technical management need business risk framing, not exploit detail. A high-level summary stating business impact plus a recommended remediation timeline conveys severity and urgency in terms they can act on, satisfying the stem's non-technical audience constraint.
- ✗
Email with subject 'URGENT' and no further details
Why it's wrong here
An 'URGENT' subject with no content conveys alarm without the vulnerability, its business impact or the action required, so management cannot prioritise or decide. It is tempting as a fast escalation trigger, but a brief summary with impact and recommended action is needed instead.
- ✗
Detailed technical exploit steps
Why it's wrong here
Detailed exploit steps assume technical fluency that non-technical management lack, so the business risk and required decision stay obscured. Such detail belongs in the technical report for engineers who will remediate. Management needs impact, likelihood and remediation cost framed in business terms.
Go deeper
Related to this question
Learn chapter
Red Team Exercises vs Penetration Tests
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Technical finding
A technical finding is a specific observation or conclusion drawn from analyzing IT systems, logs, or test results that points to a configuration issue, security vulnerability, or operational inefficiency.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.