mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is conducting an internal…
A penetration tester is conducting an internal network test. During the engagement, the tester discovers a critical vulnerability that could be exploited to gain domain admin privileges. According to best practices, how should the tester communicate this finding to the client?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately notify the client's point of contact via a secure channel
Option A is correct because best practices for penetration testing require immediately notifying the client's designated point of contact through a secure channel when a critical vulnerability—such as one enabling domain admin compromise—is discovered, so the client can begin remediation and risk mitigation without delay. This aligns with standard engagement rules of conduct and responsible disclosure, which prioritize urgent communication of high-impact findings over waiting for a scheduled report. Option B is wrong because critical findings must be proactively escalated, not withheld until the client requests a status update. Option C is wrong because waiting until the final report could leave the domain exposed to exploitation for the remainder of the engagement. Option D is wrong because exploiting the vulnerability to demonstrate impact and then attempting to "fix" it exceeds the tester's authorized scope and could cause damage or legal issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Immediately notify the client's point of contact via a secure channel
Why this is correct
A domain-admin escalation path poses immediate, severe risk to the client's environment, so the tester must report it promptly through the agreed secure channel. This satisfies the duty to disclose critical findings without waiting for the final report.
- ✗
Only communicate it if the client asks for a status update
Why it's wrong here
Withholding a critical finding until prompted delays the client's ability to mitigate an imminent domain-admin compromise. It is tempting because status updates are often scheduled at agreed checkpoints. Best practice requires prompt, proactive escalation of critical vulnerabilities outside the normal reporting cadence.
- ✗
Wait until the end of the test to include it in the formal report
Why it's wrong here
Deferring to the final report leaves the domain-admin exposure unmitigated for the engagement's remainder. It is tempting because formal reports are the standard deliverable. Critical findings demand immediate verbal or written escalation to the client contact, with the report documenting them later.
- ✗
Exploit the vulnerability to demonstrate impact and then fix it before reporting
Why it's wrong here
Exploiting to domain admin exceeds the agreed scope and risks destabilising production systems, and the tester cannot unilaterally remediate client infrastructure. It is tempting because demonstrating impact proves exploitability. Best practice is immediate notification, with exploitation only if explicitly authorised in the rules of engagement.
Go deeper
Related to this question
Learn chapter
Post-Exploitation Techniques
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.