CompTIA PenTest+ Practice Questions: Reporting and Communication

5 free, exam-style CompTIA PenTest+ (PT0-003) practice questions covering Reporting and Communication. Each question shows the correct answer and a clear explanation. Ready for the real thing? Take the full timed quiz below.

🚀 Take the full CompTIA PenTest+ quiz 📘 CompTIA PenTest+ study guide

Q1. Which finding should generally be reported with the highest priority?

Explanation: Remote code execution on exposed critical systems usually has high likelihood and impact. Learn more.

Q2. Which evidence best supports a SQL injection finding?

Explanation: High-quality findings include reproducible steps, affected parameters, impact, and evidence. Learn more.

Q3. What should an executive summary emphasize in a penetration test report?

Explanation: Executive summaries translate technical findings into risk and prioritized actions for decision-makers. Learn more.

Q4. Which report section should contain exact commands, requests, and timestamps for reproducibility?

Explanation: Technical details provide reproducible evidence and steps for remediation teams. Learn more.

Q5. Which remediation is best for command injection caused by shelling out with user input?

Explanation: Fixing command injection usually requires removing unsafe shell concatenation and applying strict input validation or safe APIs. Learn more.

More CompTIA PenTest+ practice topics