CompTIA PenTest+ (PT0-003)Engagement ManagementHard

A penetration test report will be reviewed by both C-suite executives with no technical background and the IT security team responsible for remediation. Which reporting approach BEST serves both audiences?

  1. AInclude only raw tool output from nmap, Burp Suite, and Metasploit for accuracy
  2. BWrite a single technical section using only CVSS scores without business context
  3. CInclude full working exploit code in the executive summary for transparency
  4. DProvide an executive summary describing business risk and impact, followed by a detailed technical section with reproduction steps and tool evidence
Show answer & explanation

Correct answer: D. Provide an executive summary describing business risk and impact, followed by a detailed technical section with reproduction steps and tool evidence

Effective reports are structured with an executive summary translating findings into business risk for non-technical stakeholders, followed by detailed technical findings (with reproduction steps and evidence) for the technical team to remediate.

Why the other options are wrong

  • A. Raw tool output is unreadable to executives and lacks business context.
  • B. CVSS scores alone don't convey business impact to executives.
  • C. Exploit code belongs in technical appendices, not the executive summary, and could pose risk if mishandled.

Report Structure (Executive Summary + Technical Detail)

A penetration test report format that separates business-risk-focused content for executives from detailed technical findings for remediation teams.

  • Executive summary translates risk into business terms
  • Technical section includes reproduction steps and evidence
  • Serves dual audiences with different needs

Memory trick: Top for the boss, bottom for the techs

More Engagement Management questions