Courseiva
Engagement Management →hardMultiple Choice

PT0-002 Engagement Management Practice Question

A penetration tester is conducting a red team engagement for a financial institution. The client has requested that the tester simulate a ransomware attack to test the incident response process. During the test, the tester encrypts a file share containing simulated customer data. The client's security team detects the encryption and initiates their incident response plan. Which of the following should the tester do FIRST to ensure the engagement remains within scope and does not cause operational disruption?

⚠ Common exam trap

The trap here is thinking that continuing the attack is necessary to fully test the incident response, but it risks operational disruption and going out of scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately stop all testing activities and notify the primary point of contact

In a red team engagement, when the client's incident response team detects simulated malicious activity, the tester should immediately stop testing and notify the primary point of contact. This prevents unnecessary escalation and operational disruption, and confirms that the activity is authorized. Continuing the attack or exfiltrating data could exceed the scope and cause unintended consequences. Proactive communication is key to maintaining trust and safety.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Document the encryption activity and wait for the client's incident response team to contact the tester

    Why it's wrong here

    Waiting for the client's incident response team to contact the tester is passive and may prolong the incident response process, causing unnecessary disruption. The tester should proactively notify the primary point of contact to clarify that the encryption is part of the authorized test. Documentation is important, but immediate communication is critical to prevent escalation and ensure the engagement remains within scope.

  • ✗

    Attempt to exfiltrate the simulated customer data to test data loss prevention controls

    Why it's wrong here

    Exfiltrating data, even simulated, may not be part of the agreed scope and could violate the engagement rules. The client's incident response team is already engaged, and the tester should focus on de-escalating the situation by notifying the point of contact. Exfiltration could cause additional alerts and potentially trigger legal or regulatory concerns. The tester must adhere to the scope and rules of engagement.

  • ✓

    Immediately stop all testing activities and notify the primary point of contact

    Why this is correct

    The tester should immediately stop testing and notify the primary point of contact. This action ensures that the client's incident response team is aware that the encryption is part of the authorized test, preventing unnecessary escalation or operational disruption. It also allows the client to verify that the test is within scope and that no real data is at risk. Continuing without notification could lead to confusion and potential legal issues.

  • ✗

    Continue encrypting additional file shares to fully simulate the ransomware attack

    Why it's wrong here

    Continuing to encrypt additional file shares could cause unnecessary operational disruption and may exceed the agreed scope. The client's incident response team has already detected the activity and initiated their plan. The tester should stop and notify the point of contact to confirm that the activity is authorized and prevent further disruption. Continuing could lead to unintended consequences and legal issues.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.