Courseiva
easyMultiple Choice

PT0-002 Practice Question: In a penetration test report, the executive…

In a penetration test report, the executive summary is primarily intended for which audience?

⚠ Common exam trap

It's easy for candidates to confuse the audience for the executive summary with the audience for the technical report, mistakenly thinking that all stakeholders need the same level of detail, when in fact senior management requires a non-technical, risk-focused summary while technical teams need the full exploit details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Senior management (e.g., CISO, board of directors)

The executive summary is designed for senior management (e.g., CISO, board of directors) because it provides a high-level overview of the penetration test's objectives, key findings, risk impact, and recommended strategic actions. It avoids technical jargon and detailed exploit steps, focusing instead on business risk and remediation priorities that inform decision-making and resource allocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IT system administrators

    Why it's wrong here

    IT system administrators require tactical, system-level detail—specific affected IP ranges, hostnames, patch versions, and time-sensitive remediation commands—rather than the strategic overview the executive summary provides. The findings and technical recommendations sections give them the actionable data they need to prioritize and execute fixes.

  • ✓

    Senior management (e.g., CISO, board of directors)

    Why this is correct

    The executive summary is purpose-built for senior management, such as the CISO and board of directors, who need a concise, non-technical articulation of overall security posture, business risk, financial or reputational impact, and high-level strategic recommendations. It frames the assessment in terms of risk tolerance and investment priorities, not raw technical findings.

  • ✗

    Software developers

    Why it's wrong here

    Software developers need code-specific detail—exact vulnerable functions, input validation flaws, injection points, and CWE identifiers—along with concrete remediation examples in the technical findings and remediation sections. The executive summary's aggregated risk ratings and business impact language do not provide the engineering-level specificity developers need to correct the code.

  • ✗

    External compliance auditors

    Why it's wrong here

    External compliance auditors must verify that the assessment met scope, methodology, evidence-collection, and control-mapping requirements (e.g., NIST, PCI-DSS, ISO 27001). They rely on the full report's procedural detail, raw test evidence, and gap analysis against specific controls, not the executive summary, which is deliberately tailored for internal executive decision-making.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.