PT0-002 Engagement Management Practice Question
A penetration tester discovers evidence of ongoing criminal activity, such as a data breach by an internal employee, during a white box penetration test. The client's legal team has not provided specific instructions on handling such discoveries. According to best practices and legal considerations, what should the tester do first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stop testing and contact the client's emergency contact
The tester should immediately stop testing and inform the client's emergency contact to handle the criminal activity appropriately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify law enforcement directly
Why it's wrong here
Directly notifying law enforcement bypasses the client's incident-response chain of command and may breach the penetration test agreement's confidentiality and scope clauses. The tester typically lacks the legal standing to file a criminal complaint on the client's behalf and may inadvertently compromise the admissibility of evidence by failing to follow proper chain-of-custody protocols. The correct channel is to escalate through the client's emergency contact, who has the authority to involve authorities and coordinate any legal holds.
- ✗
Continue testing and document the evidence for later reporting
Why it's wrong here
Continuing to interact with systems or individuals involved in ongoing criminal activity risks altering volatile forensic evidence and may transform the tester's legally authorized actions into unauthorized access under statutes like the CFAA, exposing the tester to civil and criminal liability. Further testing could also disrupt the client's ability to contain the incident and preserve evidence for prosecution. The engagement must stop immediately, and any evidence already gathered should be sealed and time-stamped without further analysis.
- ✓
Stop testing and contact the client's emergency contact
Why this is correct
Halting all testing and invoking the client's pre-arranged emergency contact path is the only action that both preserves the integrity of forensic evidence and keeps the engagement within its legal scope. The emergency contact is typically the client's incident-response lead or executive with authority to decide whether to involve law enforcement, issue containment orders, or terminate the test. This step ensures that the tester remains a controlled, auditable resource rather than acting unilaterally on potentially sensitive criminal matters.
- ✗
Ignore the activity and proceed as planned
Why it's wrong here
Ignoring proven criminal activity while retaining unauthorized access, even within a permitted test, creates a legal and ethical conflict because the tester could be viewed as an aider or abetter or as failing to exercise reasonable care to prevent ongoing harm. Proceeding with the test plan also risks corrupting evidence that law enforcement may later need, and it violates professional codes of conduct (e.g., (ISC)² Code of Ethics) that mandate safeguarding public welfare. The tester must act immediately to notify the client and stand down all further probing.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.