CompTIA PenTest+ (PT0-003)Engagement ManagementHard
A penetration test report will be reviewed by both C-suite executives with no technical background and the IT security team responsible for remediation. Which reporting approach BEST serves both audiences?
- AInclude only raw tool output from nmap, Burp Suite, and Metasploit for accuracy
- BWrite a single technical section using only CVSS scores without business context
- CInclude full working exploit code in the executive summary for transparency
- DProvide an executive summary describing business risk and impact, followed by a detailed technical section with reproduction steps and tool evidence
Show answer & explanationAnswer & explanation
Correct answer: D. Provide an executive summary describing business risk and impact, followed by a detailed technical section with reproduction steps and tool evidence
Effective reports are structured with an executive summary translating findings into business risk for non-technical stakeholders, followed by detailed technical findings (with reproduction steps and evidence) for the technical team to remediate.
Why the other options are wrong
- A. Raw tool output is unreadable to executives and lacks business context.
- B. CVSS scores alone don't convey business impact to executives.
- C. Exploit code belongs in technical appendices, not the executive summary, and could pose risk if mishandled.
Report Structure (Executive Summary + Technical Detail)
A penetration test report format that separates business-risk-focused content for executives from detailed technical findings for remediation teams.
- Executive summary translates risk into business terms
- Technical section includes reproduction steps and evidence
- Serves dual audiences with different needs
Memory trick: Top for the boss, bottom for the techs