mediumMultiple Choice
PT0-002 Practice Question: A client requests that the penetration tester…
A client requests that the penetration tester deliver the final report in an encrypted format via email. Which encryption method should the tester use to ensure confidentiality?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use S/MIME or PGP to encrypt the email message
The correct option is D: use S/MIME or PGP to encrypt the email message. These are end-to-end message encryption standards that protect the report's contents so only the intended recipient with the corresponding private key can decrypt it, ensuring confidentiality even if the message is stored or intercepted along the way. Option A is insufficient because TLS only encrypts the transport hop between mail servers and does not protect the message at rest or from the mail provider. Option B changes the delivery method rather than encrypting the emailed report as requested, and HTTPS only secures the download channel. Option C is weak because password-protected ZIP encryption (especially legacy ZipCrypto) is vulnerable to cracking and the password would need separate secure transmission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rely on TLS encryption for the email transport
Why it's wrong here
TLS protects the report only while in transit between mail servers; the message sits unencrypted at rest on each server and in the recipient's mailbox, so end-to-end confidentiality fails. TLS is the right control for securing transport generally, but the client explicitly requested the report itself be encrypted.
- ✗
Upload the report to a web server using HTTPS
Why it's wrong here
HTTPS secures the upload and download channel but leaves the report stored unencrypted on the web server, and access depends on link secrecy rather than cryptographic protection. HTTPS suits publishing files for controlled retrieval, not delivering a confidential report whose contents must remain encrypted at rest.
- ✗
Compress the report in a password-protected ZIP file
Why it's wrong here
Password-protected ZIP uses legacy ZipCrypto or weak AES implementations with known plaintext and brute-force weaknesses, and the password must be shared separately, so confidentiality is not assured. It tempts as a familiar convenience, but it suits casual file sharing rather than protecting sensitive client deliverables.
- ✓
Use S/MIME or PGP to encrypt the email message
Why this is correct
S/MIME and PGP provide end-to-end message-level encryption, so the report remains confidential in transit and at rest in the recipient's mailbox, unlike transport-only TLS. This satisfies the client's explicit requirement to deliver the final penetration test report in encrypted format via email.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.