Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A client requests a penetration test for a new…

A client requests a penetration test for a new e-commerce application. The application uses a microservices architecture with RESTful APIs and a React frontend. The tester recommends including both a vulnerability assessment and manual penetration testing. However, the client has a tight budget and asks to skip the vulnerability assessment to save costs. Which response best aligns with best practices?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a vulnerability assessment first and then manually validate findings.

Best practices recommend a vulnerability assessment to identify potential weaknesses, followed by manual validation to reduce false positives and exploit critical issues. Skipping the assessment may leave critical vulnerabilities undetected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform only a vulnerability assessment because it covers more vulnerabilities.

    Why it's wrong here

    Performing only a vulnerability assessment relies on automated scanners that flag known CVEs and configuration issues, but it cannot confirm exploitability or business impact. Manual penetration testing is essential for uncovering business logic flaws, chained attack paths, and false positives, which is exactly what the client expects from a penetration test. An assessment alone lacks the human validation that separates a true risk rating from a theoretical issue.

  • ✗

    Use automated scanning tools during the manual penetration test to compensate.

    Why it's wrong here

    Running automated scans only during the manual test is haphazard because scanning may be limited to the testers' current focus, leaving large parts of the application or infrastructure untested. Professional methodologies (e.g., PTES) incorporate a dedicated discovery phase before exploitation to ensure complete coverage, and ad-hoc scanning during exploitation can produce unreliable results or disrupt active tests. A separate vulnerability assessment phase is more thorough, reduces interference, and gives the test team a baseline to prioritize manual efforts.

  • ✗

    Agree to skip the vulnerability assessment and focus only on manual penetration testing.

    Why it's wrong here

    Relying purely on manual penetration testing is impractical because testers cannot inspect every endpoint, parameter, or service in the time available; automated scanners efficiently enumerate common vulnerabilities across the full scope. Without a vulnerability scan, the engagement may miss critical missing patches, weak cipher suites, or exposed administrative interfaces that a scanner would flag immediately. Consequently, skipping the assessment sacrifices breadth for depth, undermining the completeness required for a comprehensive penetration test.

  • ✓

    Conduct a vulnerability assessment first and then manually validate findings.

    Why this is correct

    Conducting a vulnerability assessment first and then manually validating each finding is the industry-standard approach (e.g., PTES and NIST SP 800-115). The scanner provides broad coverage of known vulnerabilities, while manual testing eliminates false positives, tests for exploitability, and uncovers the business logic and chaining issues that automated tools cannot detect. This combination lets the tester produce a prioritized, risk-based report that meets the client's penetration testing objective, rather than just a list of potential flaws.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.