Courseiva
Engagement Management →hardMultiple Select

PT0-002 Engagement Management Practice Question

A penetration tester discovers evidence of an ongoing criminal activity (e.g., data exfiltration by an insider) during a test. According to best practices and legal considerations, which THREE actions should the tester take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preserve all evidence and document findings for law enforcement

When discovering criminal activity, the tester should stop testing, notify the client contact, and preserve evidence for investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Preserve all evidence and document findings for law enforcement

    Why this is correct

    Preserving evidence is a forensic priority; you must create a chain of custody by recording exactly what was observed, when, and from which system, and avoid altering or deleting any data. Use write-blockers or forensic imaging if feasible, and document all findings with timestamps and system details so law enforcement can use the evidence in a legal proceeding. This action is correct because it directly supports the investigation without overstepping your engagement scope.

  • ✗

    Publicly disclose the finding on a vulnerability disclosure platform

    Why it's wrong here

    Publicly disclosing the finding on a vulnerability disclosure platform is wrong because it violates the confidential nature of the pentest engagement and the client's explicit consent boundaries. More critically, it alerts the criminal actor, giving them time to destroy evidence, change tactics, or flee, thereby compromising the ongoing investigation. Legal agreements typically require coordinated, private disclosure to the client and law enforcement, not public exposure.

  • ✓

    Immediately stop all testing activities

    Why this is correct

    Immediately stopping all testing activities is correct because any further interaction with the compromised systems could contaminate volatile evidence, alter logs, or trigger additional malicious activity. It also prevents you from exceeding the scope of your authorization, which could expose you to criminal or civil liability under computer fraud laws. Halting allows the client and law enforcement to take control in a forensically sound manner.

  • ✓

    Contact the client's emergency contact per the communication plan

    Why this is correct

    Contacting the client's emergency contact per the communication plan is correct because the pre-agreed escalation path ensures the client can activate their incident response team and coordinate with law enforcement. In ongoing criminal activity, every minute matters; the designated contact is likely the person with authority to involve authorities and preserve evidence. This action aligns with the engagement's rules of engagement and keeps you compliant with contractual notification obligations.

  • ✗

    Continue testing to gather more evidence

    Why it's wrong here

    Continuing testing to gather more evidence is wrong because ongoing unauthorized access, even with benevolent intent, may violate the Computer Fraud and Abuse Act or similar statutes, and any evidence you collect could be deemed inadmissible due to lack of proper legal authority. It also risks tipping off the attacker, modifying system state, or causing unintended disruption. Your role is to report, not to conduct an independent criminal investigation.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.