easyMultiple Choice
PT0-002 Practice Question: In a penetration test report, the executive…
In a penetration test report, the executive summary is primarily intended for which audience?
⚠ Common exam trap
It's easy for candidates to confuse the audience for the executive summary with the audience for the technical report, mistakenly thinking that all stakeholders need the same level of detail, when in fact senior management requires a non-technical, risk-focused summary while technical teams need the full exploit details.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Senior management (e.g., CISO, board of directors)
The executive summary is designed for senior management (e.g., CISO, board of directors) because it provides a high-level overview of the penetration test's objectives, key findings, risk impact, and recommended strategic actions. It avoids technical jargon and detailed exploit steps, focusing instead on business risk and remediation priorities that inform decision-making and resource allocation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IT system administrators
Why it's wrong here
IT system administrators require tactical, system-level detail—specific affected IP ranges, hostnames, patch versions, and time-sensitive remediation commands—rather than the strategic overview the executive summary provides. The findings and technical recommendations sections give them the actionable data they need to prioritize and execute fixes.
- ✓
Senior management (e.g., CISO, board of directors)
Why this is correct
The executive summary is purpose-built for senior management, such as the CISO and board of directors, who need a concise, non-technical articulation of overall security posture, business risk, financial or reputational impact, and high-level strategic recommendations. It frames the assessment in terms of risk tolerance and investment priorities, not raw technical findings.
- ✗
Software developers
Why it's wrong here
Software developers need code-specific detail—exact vulnerable functions, input validation flaws, injection points, and CWE identifiers—along with concrete remediation examples in the technical findings and remediation sections. The executive summary's aggregated risk ratings and business impact language do not provide the engineering-level specificity developers need to correct the code.
- ✗
External compliance auditors
Why it's wrong here
External compliance auditors must verify that the assessment met scope, methodology, evidence-collection, and control-mapping requirements (e.g., NIST, PCI-DSS, ISO 27001). They rely on the full report's procedural detail, raw test evidence, and gap analysis against specific controls, not the executive summary, which is deliberately tailored for internal executive decision-making.
Go deeper
Related to this question
Learn chapter
Penetration Testing Tools
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.