PT0-002 Engagement Management Practice Question
Which TWO of the following are typical deliverables of a penetration test?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Technical findings and remediation guidance
Standard deliverables include an executive summary for management and technical findings for remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Technical findings and remediation guidance
Why this is correct
This is the core of a penetration test report, providing detailed descriptions of discovered vulnerabilities, including affected systems, exploitation steps, and impact. It must also include actionable remediation steps, such as patching, configuration changes, or code fixes, so the client can address risks. Without this, the report would not meet the engagement's objective of enabling the client to reduce risk.
- ✗
User credentials for all accounts
Why it's wrong here
A penetration test report does not include a comprehensive list of user credentials, as these are highly sensitive and their distribution would expand the attack surface. While the report may reference compromised accounts as evidence of impact, actual passwords or password hashes are typically omitted or redacted. Including all accounts would pose a severe security risk and is not a professional deliverable.
- ✗
Source code of the tested application
Why it's wrong here
The deliverable is not the entire source code, but the findings derived from analysis, often with small, relevant code snippets illustrating the root cause. Supplying the full source code would expose intellectual property and is generally unnecessary for the client to understand the vulnerabilities. Clients already possess their own source code; the report only needs to show where flaws exist and how to remedy them.
- ✗
Video recording of the testing process
Why it's wrong here
Although a tester may capture screenshots, logs, or screen recordings as evidence, a full video recording is not a standard deliverable due to file size, confidentiality of tooling, and lack of added value for remediation. Text-based evidence and well-annotated findings are more practical and searchable. Clients rarely request video, and it is not part of the customary report package.
- ✓
Executive summary
Why this is correct
This is a crucial deliverable for management and non-technical stakeholders, summarizing the overall security posture, key risks, and business impact in plain language. It typically includes critical/high findings, risk scores, and strategic recommendations, allowing decision-makers to prioritize security investments. It also sets the tone for the technical sections that follow.
Go deeper
Related to this question
Learn chapter
Writing Penetration Test Reports
Key term
Executive summary
An executive summary is a concise overview of a longer document that highlights the key points, findings, and recommendations so busy stakeholders can quickly grasp the essential information without reading the full report.
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.