Courseiva
hardMultiple Select

PT0-002 Practice Question: A penetration tester discovers a critical…

A penetration tester discovers a critical vulnerability that cannot be fully remediated immediately. The client asks for recommendations. Which THREE of the following should the tester include?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement compensating controls to reduce risk.

When full remediation is not possible, recommend compensating controls, prioritize critical fixes, and offer retesting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement compensating controls to reduce risk.

    Why this is correct

    When a critical vulnerability cannot be patched immediately, implementing compensating controls—such as a web application firewall (WAF) rule to block exploit payloads, network segmentation to limit lateral movement, or additional authentication requirements—provides an interim layer of risk reduction. These controls do not remove the underlying flaw but reduce the likelihood of successful exploitation while a permanent fix is developed. This is a proactive and accepted practice in vulnerability management, as it buys time without leaving the asset fully exposed.

  • ✓

    Prioritize remediation of this vulnerability first.

    Why this is correct

    A critical vulnerability, by definition, poses an immediate and high-impact threat to the confidentiality, integrity, or availability of the system, often enabling remote code execution or unauthorized data access. Consequently, remediation must be prioritized above lower-severity findings because the risk of exploitation is high and the potential business impact is severe. Delaying remediation increases the window of exposure, making this the first action in any responsible vulnerability management process.

  • ✗

    Delete the finding from the report.

    Why it's wrong here

    Deleting a finding from the report violates the core ethical obligations of a penetration tester to provide accurate and complete information about discovered vulnerabilities. Such censorship would also hide a known critical risk from the client, potentially leading to a security breach due to lack of awareness. Furthermore, it undermines the credibility and contractual integrity of the assessment, and in some jurisdictions, could even constitute professional misconduct or negligence.

  • ✓

    Offer to retest after remediation is applied.

    Why this is correct

    Offering to retest after the client applies a remediation confirms that the vulnerability is actually resolved, not just theoretically patched. A retest involves re-running the original exploit or check against the system to verify the fix is effective and that no bypass or regression has been introduced. This step is essential for closing the loop and ensuring the organization achieves a genuinely secure state, and it also helps the pentester document the effectiveness of the remediation for compliance purposes.

  • ✗

    Ignore the vulnerability until the next test.

    Why it's wrong here

    Ignoring a critical vulnerability until the next scheduled test is reckless, as a critical flaw can be leveraged by attackers at any moment, and a typical retest interval of months provides a huge window of opportunity for exploitation. A penetration tester has a professional duty to report high-risk findings immediately and to ensure they are acted upon, not to defer them. This approach abandons the client to significant risk and contradicts the purpose of the assessment, which is to identify and mitigate risks in a timely manner.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.