PT0-002 Engagement Management Practice Question
A penetration tester is conducting a red team engagement for a financial institution. The client has requested that the tester simulate a ransomware attack to test the incident response process. During the test, the tester encrypts a file share containing simulated customer data. The client's security team detects the encryption and initiates their incident response plan. Which of the following should the tester do FIRST to ensure the engagement remains within scope and does not cause operational disruption?
⚠ Common exam trap
The trap here is thinking that continuing the attack is necessary to fully test the incident response, but it risks operational disruption and going out of scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately stop all testing activities and notify the primary point of contact
In a red team engagement, when the client's incident response team detects simulated malicious activity, the tester should immediately stop testing and notify the primary point of contact. This prevents unnecessary escalation and operational disruption, and confirms that the activity is authorized. Continuing the attack or exfiltrating data could exceed the scope and cause unintended consequences. Proactive communication is key to maintaining trust and safety.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Document the encryption activity and wait for the client's incident response team to contact the tester
Why it's wrong here
Waiting for the client's incident response team to contact the tester is passive and may prolong the incident response process, causing unnecessary disruption. The tester should proactively notify the primary point of contact to clarify that the encryption is part of the authorized test. Documentation is important, but immediate communication is critical to prevent escalation and ensure the engagement remains within scope.
- ✗
Attempt to exfiltrate the simulated customer data to test data loss prevention controls
Why it's wrong here
Exfiltrating data, even simulated, may not be part of the agreed scope and could violate the engagement rules. The client's incident response team is already engaged, and the tester should focus on de-escalating the situation by notifying the point of contact. Exfiltration could cause additional alerts and potentially trigger legal or regulatory concerns. The tester must adhere to the scope and rules of engagement.
- ✓
Immediately stop all testing activities and notify the primary point of contact
Why this is correct
The tester should immediately stop testing and notify the primary point of contact. This action ensures that the client's incident response team is aware that the encryption is part of the authorized test, preventing unnecessary escalation or operational disruption. It also allows the client to verify that the test is within scope and that no real data is at risk. Continuing without notification could lead to confusion and potential legal issues.
- ✗
Continue encrypting additional file shares to fully simulate the ransomware attack
Why it's wrong here
Continuing to encrypt additional file shares could cause unnecessary operational disruption and may exceed the agreed scope. The client's incident response team has already detected the activity and initiated their plan. The tester should stop and notify the point of contact to confirm that the activity is authorized and prevent further disruption. Continuing could lead to unintended consequences and legal issues.
Go deeper
Related to this question
Learn chapter
DCSync Attack and Domain Replication
Key term
Red team
A red team is a group of security professionals who simulate real-world attacks on an organization's systems, people, and facilities to test the effectiveness of its defenses.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.