PT0-002 Engagement Management Practice Question
A company hires a penetration testing firm to simulate the tactics, techniques, and procedures of a real adversary. The engagement includes attempting to achieve specific objectives without being detected. This type of engagement is best described as:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Red team exercise
A red team exercise is an adversary simulation that aims to test detection and response capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network penetration test
Why it's wrong here
A network penetration test is scoped to identifying and exploiting vulnerabilities in the target network infrastructure, such as unpatched services, weak credentials, or misconfigured firewalls, and it typically ceases once an agreed-upon proof of concept is demonstrated. It does not attempt to emulate a real adversary's end-to-end campaign, which would involve stealthy reconnaissance, evading detection, lateral movement, and achieving a specific objective beyond the network itself. This type of assessment is often compliance-driven and captures a point-in-time snapshot of technical weaknesses rather than a sustained, operationally realistic simulation.
- ✗
Web application penetration test
Why it's wrong here
A web application penetration test focuses exclusively on the application layer, examining for OWASP Top Ten flaws like SQL injection, cross-site scripting, and broken access control, and does so within the scope of the application's code, authentication flows, and business logic. It is commonly performed in a white-box or grey-box manner with valid credentials and defined test cases, and it does not include the broader adversarial behaviors such as initial network reconnaissance, host pivoting, or command-and-control. The goal is to enumerate and fix app-specific vulnerabilities, not to test the blue team's ability to detect and respond to a realistic attack chain.
- ✗
Social engineering engagement
Why it's wrong here
A social engineering engagement is a targeted assessment of the human defenses, using phishing, vishing, pretexting, or physical impersonation to see whether employees will reveal information, click malicious links, or grant access. While social engineering is often a key delivery mechanism within a red team exercise, a standalone engagement stops at human compromise and does not proceed with the technical follow-through like payload execution, establishing persistence, moving laterally, or exfiltrating data. It measures security awareness and policy adherence in isolation, not the integrated people-process-technology effectiveness that a full adversarial simulation demands.
- ✓
Red team exercise
Why this is correct
A red team exercise is an objective-based, adversarial simulation that mimics the tactics, techniques, and procedures (TTPs) of a specific real-world threat actor, with rules of engagement allowing stealth, creativity, and a kill-chain approach. It tests not just the existence of vulnerabilities but also the blue team's detection, response, and recovery capabilities by conducting a realistic attack lifecycle—reconnaissance, initial compromise, lateral movement, privilege escalation, and impact or exfiltration. Unlike a standard pen test, a red team engagement is often conducted without the defensive team being forewarned, and it succeeds only if it achieves a predefined business objective without being caught, making it the closest simulation of a genuine attack.
Go deeper
Related to this question
Learn chapter
Penetration Testing Tools
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Adversary simulation
A cybersecurity exercise where a team mimics the tactics, techniques, and procedures of a real attacker to test an organization's defenses without causing actual harm.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.