Courseiva
Engagement Management →easyMultiple Choice

PT0-002 Engagement Management Practice Question

A company hires a penetration testing firm to simulate the tactics, techniques, and procedures of a real adversary. The engagement includes attempting to achieve specific objectives without being detected. This type of engagement is best described as:

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Red team exercise

A red team exercise is an adversary simulation that aims to test detection and response capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network penetration test

    Why it's wrong here

    A network penetration test is scoped to identifying and exploiting vulnerabilities in the target network infrastructure, such as unpatched services, weak credentials, or misconfigured firewalls, and it typically ceases once an agreed-upon proof of concept is demonstrated. It does not attempt to emulate a real adversary's end-to-end campaign, which would involve stealthy reconnaissance, evading detection, lateral movement, and achieving a specific objective beyond the network itself. This type of assessment is often compliance-driven and captures a point-in-time snapshot of technical weaknesses rather than a sustained, operationally realistic simulation.

  • ✗

    Web application penetration test

    Why it's wrong here

    A web application penetration test focuses exclusively on the application layer, examining for OWASP Top Ten flaws like SQL injection, cross-site scripting, and broken access control, and does so within the scope of the application's code, authentication flows, and business logic. It is commonly performed in a white-box or grey-box manner with valid credentials and defined test cases, and it does not include the broader adversarial behaviors such as initial network reconnaissance, host pivoting, or command-and-control. The goal is to enumerate and fix app-specific vulnerabilities, not to test the blue team's ability to detect and respond to a realistic attack chain.

  • ✗

    Social engineering engagement

    Why it's wrong here

    A social engineering engagement is a targeted assessment of the human defenses, using phishing, vishing, pretexting, or physical impersonation to see whether employees will reveal information, click malicious links, or grant access. While social engineering is often a key delivery mechanism within a red team exercise, a standalone engagement stops at human compromise and does not proceed with the technical follow-through like payload execution, establishing persistence, moving laterally, or exfiltrating data. It measures security awareness and policy adherence in isolation, not the integrated people-process-technology effectiveness that a full adversarial simulation demands.

  • ✓

    Red team exercise

    Why this is correct

    A red team exercise is an objective-based, adversarial simulation that mimics the tactics, techniques, and procedures (TTPs) of a specific real-world threat actor, with rules of engagement allowing stealth, creativity, and a kill-chain approach. It tests not just the existence of vulnerabilities but also the blue team's detection, response, and recovery capabilities by conducting a realistic attack lifecycle—reconnaissance, initial compromise, lateral movement, privilege escalation, and impact or exfiltration. Unlike a standard pen test, a red team engagement is often conducted without the defensive team being forewarned, and it succeeds only if it achieves a predefined business objective without being caught, making it the closest simulation of a genuine attack.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.