Courseiva
Engagement Management →easyMultiple Select

PT0-002 Engagement Management Practice Question

Which TWO of the following are typical deliverables of a penetration test?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Technical findings and remediation guidance

Standard deliverables include an executive summary for management and technical findings for remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Technical findings and remediation guidance

    Why this is correct

    This is the core of a penetration test report, providing detailed descriptions of discovered vulnerabilities, including affected systems, exploitation steps, and impact. It must also include actionable remediation steps, such as patching, configuration changes, or code fixes, so the client can address risks. Without this, the report would not meet the engagement's objective of enabling the client to reduce risk.

  • ✗

    User credentials for all accounts

    Why it's wrong here

    A penetration test report does not include a comprehensive list of user credentials, as these are highly sensitive and their distribution would expand the attack surface. While the report may reference compromised accounts as evidence of impact, actual passwords or password hashes are typically omitted or redacted. Including all accounts would pose a severe security risk and is not a professional deliverable.

  • ✗

    Source code of the tested application

    Why it's wrong here

    The deliverable is not the entire source code, but the findings derived from analysis, often with small, relevant code snippets illustrating the root cause. Supplying the full source code would expose intellectual property and is generally unnecessary for the client to understand the vulnerabilities. Clients already possess their own source code; the report only needs to show where flaws exist and how to remedy them.

  • ✗

    Video recording of the testing process

    Why it's wrong here

    Although a tester may capture screenshots, logs, or screen recordings as evidence, a full video recording is not a standard deliverable due to file size, confidentiality of tooling, and lack of added value for remediation. Text-based evidence and well-annotated findings are more practical and searchable. Clients rarely request video, and it is not part of the customary report package.

  • ✓

    Executive summary

    Why this is correct

    This is a crucial deliverable for management and non-technical stakeholders, summarizing the overall security posture, key risks, and business impact in plain language. It typically includes critical/high findings, risk scores, and strategic recommendations, allowing decision-makers to prioritize security investments. It also sets the tone for the technical sections that follow.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.