easyMultiple Choice
PT0-002 Practice Question: Which section of a penetration testing report…
Which section of a penetration testing report should provide a high-level overview of the test results using business language and strategic recommendations?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Executive summary
The executive summary is designed for non-technical stakeholders to understand the overall risk and key actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Executive summary
Why this is correct
The executive summary is the report section intended for senior management and other non-technical stakeholders. It translates the engagement's findings into business risk language, concisely summarizing the overall security posture and prioritizing strategic recommendations. This section deliberately avoids technical jargon and focuses on the high-level impact, making it the appropriate place for a macrolevel account of the assessment's key takeaways.
- ✗
Technical findings section
Why it's wrong here
The technical findings section is designed for IT security personnel and system owners who need to understand the exact attack chain, affected systems, and supporting evidence. It contains detailed technical explanations, such as specific vulnerabilities, exploit steps, and network artifacts, rather than a high-level business overview. Because this section assumes preexisting technical knowledge, it would not satisfy the requirement for a non-technical summary.
- ✗
Remediation recommendations
Why it's wrong here
Remediation recommendations offer prioritized, actionable steps to mitigate each identified vulnerability, often with configuration guidance and patch references. These recommendations are solution-oriented and require technical context to implement, making them a downstream component of the technical reporting. They do not serve as the concise, business-focused synopsis that a report's executive summary provides.
- ✗
Appendices
Why it's wrong here
Appendices house supporting raw data, including scope definitions, detailed test methodology, tool outputs, and any contractual documentation. This material is supplemental and intended for auditability and validation by reviewers who want to trace the evidence base. Since appendices are inherently detailed and reference-heavy, they are unsuitable for delivering a concise strategic overview.
Go deeper
Related to this question
Learn chapter
Mobile Application Testing
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.