Practise writing the executive summary of a penetration test report: business impact, plain language, risk posture, and key recommendations.
0 / 10 completed
1 / 10
The executive summary is written primarily for ___.
Executives need business risk and decisions, not packet captures; the summary translates technical findings into terms they can act on.
2 / 10
Which sentence frames a finding in business-impact terms?
Leadership cares about consequences (data loss, fines, reputation); tying findings to impact drives investment decisions.
3 / 10
A good executive summary describes the overall ___ rather than every individual bug.
Summarising the organisation's overall risk posture gives leaders the big picture; details belong in the technical findings section.
4 / 10
Which is appropriate language for an executive summary?
Plain language ensures non-technical readers understand; technical artefacts go in appendices for engineers.
5 / 10
The summary should end with a few high-level ___.
Concise recommendations tell leadership what to prioritise and fund, closing the loop from problem to action.
6 / 10
During a post-pentest meeting with the product manager, Sarah needs to concisely summarize the key vulnerabilities discovered. Which of the following statements would be MOST effective in conveying this information?
Option 1 focuses on the business impact – data breaches and service disruptions – which is crucial for a product manager. Options 2 and 3 are too technical and lack context about the potential consequences. Option 4 is far too vague and doesn't highlight the severity or risk associated with the vulnerabilities.
7 / 10
You're reviewing a code change from Alex that includes a description of a potential privilege escalation vulnerability. Alex writes in the commit message: 'Fixed a bug where users could gain admin access.' Which phrasing best improves this message to align with pentest executive summary standards?
Option 0 is the most precise and professional. It clearly states the *impact* of the vulnerability – unauthorized administrative privileges – using formal language suitable for an executive summary. Options 1 and 2 are too vague, while option 3 focuses on the technical fix rather than the risk.
8 / 10
As a security analyst, you've identified a critical vulnerability in a recently deployed API endpoint. You send a Slack message to your team lead, David. Which of the following messages is MOST appropriate for capturing this finding and prompting action?
Option 1 provides David with a clear and concise description of the vulnerability – including the affected endpoint and potential impact (unauthorized data access) – allowing him to quickly assess the situation. Options 2 and 3 are too informal, while option 4 lacks any specific detail.
9 / 10
You've submitted a pull request to address a cross-site scripting (XSS) vulnerability. The PR description currently reads: 'Fixed XSS.' Which of the following descriptions would be more effective for documenting this finding in the context of an executive summary?
Option 1 clearly explains the *impact* of the vulnerability – allowing attackers to inject malicious scripts – which is essential for an executive summary. Options 2 and 3 are too technical, while option 4 focuses on the fix without detailing the risk.
10 / 10
During a daily stand-up, you need to briefly update your team on the progress of the pentest. You've discovered several vulnerabilities related to insecure direct object references. Which statement is BEST for conveying this information concisely and effectively?
Option 2 provides a clear and focused description of the vulnerability – insecure direct object references – without getting bogged down in technical details. It highlights the risk associated with the vulnerabilities, which is important for a quick update. Options 1 and 3 are too vague, while option 4 lacks specific context.
What will I practise in "Pentest Executive Summary Writing"?
This module focuses on Pentest Communication — real workplace phrasing you'll use on the job. It contains 10 scenario-based multiple-choice questions with instant feedback.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account or sign-up required.
How many questions does this exercise have?
This module includes 10 questions. Each one gives an immediate right/wrong result plus a full explanation of the correct phrasing.
What happens if I answer a question incorrectly?
You'll see the correct answer highlighted straight away, along with a plain-English explanation of why it's right and why the other options don't fit — mistakes are part of the learning here.
Can I retry the exercise if I want a better score?
Yes — use the 'Try again' button on the results screen to reset your score and go through the questions again. There's no limit on attempts.
Who is this Pentest Communication exercise for?
It's aimed at IT professionals with working English who want to sound more natural and precise around pentest communication — useful whether you're preparing for real conversations at work or just building confidence with the vocabulary.
Do I need an account to track my progress?
No account is needed. Your progress through the exercise is tracked locally in your browser for the current session, and you can replay the module at any time.
How is this different from reading a blog article?
This exercise is an interactive drill that tests and reinforces specific phrasing through multiple-choice questions with instant feedback, while blog articles explain concepts and vocabulary in prose. The two work well together.
Where can I find more Pentest Communication exercises?
See the Pentest Communication hub for more modules like this one, or browse the full Exercises page for other IT-English topics.
Can I complete this exercise on my phone?
Yes — every exercise on CoderSlingo is fully responsive and works on phones and tablets, so you can practise anywhere.