hardMultiple Select
PT0-002 Practice Question: Which THREE of the following are best practices…
Which THREE of the following are best practices for writing a penetration test report?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Organize findings by severity and likelihood
Option A is correct because organizing findings by severity and likelihood (e.g., using a risk matrix combining CVSS base scores with exploitability and business impact) lets stakeholders prioritize remediation of the highest-risk issues first. Option B is correct because a glossary of terms makes the report accessible to non-technical readers such as executives and managers, who often approve budgets and remediation efforts but lack security vocabulary. Option D is correct because each finding should include clear, actionable remediation steps (specific patches, configuration changes, or compensating controls) so the client can actually fix the issue rather than just knowing it exists. Option C is not a best practice because excessive technical jargon obscures meaning and alienates non-technical stakeholders; reports should be precise but audience-appropriate. Option E is not a best practice because including duplicates and false positives dilutes the report, wastes client time, and undermines credibility; findings should be validated and deduplicated before inclusion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Organize findings by severity and likelihood
Why this is correct
Grouping findings by severity and likelihood lets stakeholders triage remediation by actual risk, satisfying the report's need to prioritise action. This ordering maps directly to the risk rating assigned to each vulnerability, ensuring critical, easily exploitable issues are addressed before low-impact ones.
- ✓
Include a glossary of terms for non-technical readers
Why this is correct
A glossary translates technical jargon such as CVSS, payload and lateral movement for executives and managers who lack security backgrounds. This satisfies the report's requirement to communicate findings clearly to non-technical decision-makers who approve remediation budgets.
- ✗
Use technical jargon to demonstrate expertise
Why it's wrong here
Jargon obscures findings for the executives and asset owners who authorise remediation, so it undermines the report's purpose of driving action. Technical depth belongs in an appendix; the correct practice is clear language matched to the audience, reserving precise terminology for the technical remediation steps.
- ✓
Provide clear remediation steps for each finding
Why this is correct
Remediation steps translate each finding into concrete corrective action, letting the client fix vulnerabilities rather than merely knowing they exist. This satisfies the report's practical purpose, ensuring findings are actionable and prioritised so the organisation can reduce risk efficiently after the engagement concludes.
- ✗
Include all vulnerabilities discovered even if they are duplicates or false positives
Why it's wrong here
Listing duplicates and false positives inflates the findings count and erodes trust in the report, since readers cannot distinguish verified issues from noise. Reports should present validated, de-duplicated findings with evidence; raw scanner output belongs in an appendix, not the main body.
Go deeper
Related to this question
Learn chapter
Physical Security Testing Techniques
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
CVSS
The Common Vulnerability Scoring System (CVSS) is a standardized framework used to rate the severity of security vulnerabilities on a scale from 0 to 10.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.