easyMultiple Choice
PT0-002 Practice Question: Is the MOST appropriate format for delivering the…
Which of the following is the MOST appropriate format for delivering the final penetration test report to the client?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PDF with password protection and digital signature.
A PDF with password protection and digital signature ensures the penetration test report is delivered confidentially, tamper-evident, and verifiably authentic to the client. Password protection restricts access to authorized recipients, while the digital signature provides integrity and non-repudiation, which are critical for sensitive security findings. In contrast, an HTML file hosted on the tester's website (A) exposes the report publicly and lacks access control, a plain text file (B) offers no confidentiality or authenticity protections, and a Word document with tracked changes (C) may inadvertently reveal internal edits, comments, or metadata and is easily altered.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HTML file hosted on the tester's website.
Why it's wrong here
Hosting the report on the tester's own website places sensitive vulnerability data outside the client's control and may breach confidentiality terms. Web-hosted HTML suits public documentation; a penetration test report demands controlled, authenticated delivery to the client.
- ✗
Plain text file with no formatting.
Why it's wrong here
A plain text file strips tables, severity ratings and screenshots that clients need to triage findings, and offers no structure for executive and technical audiences. Plain text suits raw tool output or logs, not a formal deliverable requiring consistent presentation.
- ✗
Microsoft Word document with tracked changes.
Why it's wrong here
Tracked changes expose internal drafting edits and comments, and the client could accept or reject revisions, undermining the report's authority as a final record. Word documents suit collaborative drafting, not the immutable deliverable issued at engagement close.
- ✓
PDF with password protection and digital signature.
Why this is correct
Password protection plus a digital signature satisfies the client-delivery constraint: encryption guards report confidentiality in transit, while the signature lets the client verify authenticity and detect tampering. A plain PDF or unprotected archive fails both requirements, so this format is the most appropriate for the final penetration test report.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.