mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is documenting evidence for…
A penetration tester is documenting evidence for a finding. Which of the following is the least appropriate type of evidence to include?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Proof-of-concept code that deletes user data to prove impact
Proof-of-concept code should demonstrate exploitability without causing harm. Including a fully functional exploit that could cause harm is irresponsible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Screenshot of the vulnerability with timestamp
Why it's wrong here
A screenshot of the vulnerability with a timestamp is appropriate evidence because it provides a clear, non-destructive visual record of the finding, including the affected URL, parameters, and time of detection. This type of evidence is commonly accepted in reports and does not risk system damage or data loss, so it is not the incorrect option in a question about avoiding destructive testing practices.
- ✓
Proof-of-concept code that deletes user data to prove impact
Why this is correct
A proof-of-concept that deletes user data is destructive and irresponsible; it goes beyond verification by causing irreversible harm to the target environment, potentially violating the rules of engagement and breaking production data. Penetration testers should demonstrate impact using non-destructive methods, such as reading a file or modifying a test record, to avoid unintended consequences. This is the option that must be avoided.
- ✗
Network capture showing the exploit traffic
Why it's wrong here
Network capture showing the exploit traffic is valid evidence because it documents the actual exploit attempt and server responses in a passive, non-invasive manner, preserving packet details such as source/destination IPs, payloads, and timestamps. This evidence is essential for reconstructing the attack chain and is fully consistent with responsible testing practices, making it an appropriate choice rather than the destructive one.
- ✗
Output from the vulnerability scanner
Why it's wrong here
Output from the vulnerability scanner is acceptable evidence because it provides automated, repeatable confirmation of the vulnerability, including severity ratings, affected assets, and scan parameters, without altering or deleting data. Scanner output is a standard artifact in pentest reports and helps correlate manual findings, so it clearly does not represent the risky, destructive behavior the question targets.
Go deeper
Related to this question
Learn chapter
Red Team Exercises vs Penetration Tests
Key term
Exploitability
Exploitability is a measure of how easy or difficult it is for an attacker to take advantage of a vulnerability in a system or software.
Key term
Evidence
Evidence is any data or documentation that proves an event, action, or condition occurred, crucial for verifying compliance, security incidents, or system changes.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.