Courseiva
easyMultiple Choice

PT0-002 Practice Question: When writing the executive summary of a…

When writing the executive summary of a penetration test report, which of the following is the most appropriate language to use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Business-oriented language focusing on risk, impact, and high-level recommendations.

The executive summary should be written in business language, avoiding technical jargon, to convey the overall risk and strategic recommendations to non-technical stakeholders.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A list of all vulnerabilities sorted by CVSS score without context.

    Why it's wrong here

    An executive summary must synthesize findings into actionable strategic insight; a context-free list of CVSS scores forces executives to interpret numerical severity ratings without asset criticality, exploitability in the organization's environment, or potential business impact. Such a list overloads a non-technical audience while omitting the 'so what' that justifies prioritization of remediation funding, making it an ineffective executive communication tool.

  • ✗

    Raw output from scanning tools and network packet captures.

    Why it's wrong here

    Raw scan output and packet captures are unprocessed, voluminous artifacts that typically contain false positives, irrelevant chatter, and ambiguous protocol details; including them in an executive summary buries the key messages under technical noise that an executive audience cannot parse. These artifacts belong in the report's appendices or technical findings section, where remediation teams can inspect exact evidence, while the executive summary must instead present distilled conclusions and business-level recommendations.

  • ✓

    Business-oriented language focusing on risk, impact, and high-level recommendations.

    Why this is correct

    The executive summary is written for decision-makers who care about exposure, not exploit syntax; it translates technical test results into business risk terms such as potential financial loss, regulatory fines, IP theft, or operational downtime, and pairs each high-level finding with a recommended strategic direction. By focusing on risk, impact, and high-level recommendations, it gives executives the context they need to authorize remediation efforts and aligns the pentest's outcome with organizational priorities.

  • ✗

    Detailed technical descriptions of each vulnerability and exploit code used.

    Why it's wrong here

    An executive summary is intended for non-technical stakeholders who require a high-level overview of risks and business impact, not the exploit code or detailed vulnerability descriptions. This option is tempting because such technical depth belongs in the technical findings section of the report, where it supports remediation teams. It would be correct if the question asked for the technical appendix or detailed vulnerability breakdown.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.