PT0-002 · Question #511
In a standard engagement, a post-report document is provided outside of the report. This document: - Does not contain specific findings - Exposes vulnerabilities - Can be shared publicly with outside
The correct answer is C. Executive summary. An executive summary is a high-level document written for non-technical audiences (executives, board members, external stakeholders). It does not contain specific technical findings or detailed vulnerability data, but it does convey the overall security posture and the presence o
Question
In a standard engagement, a post-report document is provided outside of the report. This document:
- Does not contain specific findings
- Exposes vulnerabilities
- Can be shared publicly with outside parties that do not have an in-
depth understanding about the client's network Which of the following documents is described?
Options
- AAttestation letter
- BFindings report
- CExecutive summary
- DNon-disclosure agreement
How the community answered
(48 responses)- B6% (3)
- C90% (43)
- D4% (2)
Explanation
An executive summary is a high-level document written for non-technical audiences (executives, board members, external stakeholders). It does not contain specific technical findings or detailed vulnerability data, but it does convey the overall security posture and the presence of vulnerabilities at a high level. Because it lacks sensitive technical specifics, it can be shared more broadly with outside parties. An attestation letter (A) formally certifies that testing occurred but doesn't describe vulnerabilities. A findings report (B) contains detailed technical findings and is not safe for public sharing. A non-disclosure agreement (D) is a legal contract about confidentiality, not a post-test document describing results.
Topics
Community Discussion
No community discussion yet for this question.