hardMultiple Select
PT0-002 Practice Question: Which THREE of the following are important…
Which THREE of the following are important elements to include in the remediation section of a penetration test report? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Priority levels (e.g., Critical, High, Medium) based on risk.
Options A, C, and D are correct. Remediation should include specific steps, reference to industry standards, and priority based on risk. Option B is not a standard part of remediation; it's for methodology. Option E is about disclosure, not remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Priority levels (e.g., Critical, High, Medium) based on risk.
Why this is correct
Priority levels are a core component of a remediation plan because they translate technical severity into business risk. By classifying each vulnerability as Critical, High, Medium, or Low (often derived from CVSS scores, asset criticality, and exploitability), the client can focus on the most urgent issues first and allocate resources efficiently. Without clear prioritization, the client may waste effort on low-impact flaws while critical exposures remain unpatched.
- ✗
A list of all external parties notified about the vulnerabilities.
Why it's wrong here
A list of external parties notified about the vulnerabilities is not part of a remediation plan; it belongs in the disclosure or incident response section of a report. Remediation is about technical actions to reduce risk, whereas external notification is a compliance or legal obligation (e.g., GDPR breach notification, CISA reporting). Including it here would blur the line between fixing the problem and managing the aftermath, which is beyond the scope of actionable remediation steps.
- ✓
Step-by-step instructions to fix each vulnerability.
Why this is correct
Step-by-step remediation instructions are essential because they give the client's technical staff a concrete, repeatable path to eliminate the vulnerability. Effective instructions include exact commands, configuration changes, or patch versions, and should be validated by the tester to ensure they work in the intended environment. Vague advice like 'apply vendor patch' is insufficient because it leaves room for misinterpretation and incomplete fixes.
- ✓
CVE identifiers or references to industry best practices.
Why this is correct
CVE identifiers and references to industry best practices (e.g., CIS Benchmarks, OWASP) provide authoritative context that supports the remediation effort. These references allow the client to verify the severity, understand the root cause, and locate vendor advisories or configuration guides. This also adds credibility to the report and helps the client justify the remediation to management or auditors.
- ✗
Detailed timeline of when each finding was discovered.
Why it's wrong here
A detailed timeline of when each finding was discovered is more appropriate for the findings log or an appendix that documents the engagement's chronology. The remediation plan should focus on the 'what' and 'how' of fixing vulnerabilities, not the 'when' of their detection. Including a discovery timeline here would distract from actionable guidance and could unintentionally shift focus to investigation process rather than forward-looking fixes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.