mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is documenting evidence for…
A penetration tester is documenting evidence for a finding and takes a screenshot. Which of the following is the most important metadata to include with the screenshot?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A timestamp
Timestamps provide context and prove when the evidence was captured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The tool version used
Why it's wrong here
While recording the tool version (e.g., Nmap 7.94, Burp Suite 2023.1) does provide helpful context for reproducibility and for ruling out version-specific false positives, it does not establish the authorized timeframe in which the evidence was collected. Rules of engagement typically define a precise testing window, and only a timestamp can prove that a finding was discovered within that window, so the tool version alone cannot support the temporal chain of custody. It is supplementary metadata, not a critical element of evidentiary integrity.
- ✓
A timestamp
Why this is correct
A timestamp, ideally with an explicit timezone offset (e.g., 2025-04-11T14:32:07Z), is critical because it binds the evidence to a specific moment in time, proving that the finding was captured during the authorized penetration testing period. It supports the evidentiary chain of custody and enables correlation with external logs (e.g., target authentication logs, network captures) to corroborate that the reported activity actually occurred. Without an accurate timestamp, a screenshot can be challenged as having been taken before, during, or after the engagement, potentially invalidating the entire finding in a compliance or legal review. Therefore, the timestamp is essential for establishing both the validity and the reliability of the evidence.
- ✗
The file size of the screenshot
Why it's wrong here
The file size of a screenshot (e.g., 512 KB) is entirely irrelevant to the validity or integrity of the evidence, because it conveys no information about when, where, or how the capture was made. A file size is a function of image dimensions and compression settings, and it cannot be used to authenticate the content or detect tampering. Even if the file size were unusual, it would not carry the same evidentiary weight as a timestamp or cryptographic hash. Thus, file size is a low-value attribute that does not support the finding.
- ✗
The tester's name
Why it's wrong here
The tester's name (e.g., "John Smith") offers some value for internal accountability, such as identifying who is responsible for the finding, but it does not strengthen the technical validity of the evidence itself. An individual's identity is subjective personnel metadata, not a property of the captured artifact, and it has no bearing on whether the screenshot accurately depicts the vulnerable state of the target system. In evidentiary reviews, the focus is on the artifact's authenticity and its temporal context, not on the person who happened to press the capture button. Consequently, the tester's name is not essential for evidence validity and is secondary to a timestamp.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.