hardMultiple Choice
PT0-002 Practice Question: A penetration tester is finalizing a report and…
A penetration tester is finalizing a report and needs to ensure that sensitive data discovered during the test (e.g., password hashes, PII) is handled appropriately. Which of the following is the BEST practice?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sanitize the data by redacting or replacing with placeholders.
Option A is correct because sanitizing sensitive findings by redacting or replacing them with placeholders (e.g., masking password hashes or PII) preserves the evidentiary value of the report while preventing unnecessary exposure of the actual secrets to readers. This aligns with penetration testing reporting best practices and data-handling standards such as those in PTES and OWASP, which call for minimizing sensitive data in deliverables. Option B is wrong because destroying all copies and omitting the data removes the evidence needed to validate and remediate the findings. Option C is wrong because an oral-only debrief provides no durable, auditable record for remediation or compliance. Option D is wrong because including raw password hashes or PII, even encrypted, unnecessarily expands the exposure surface and violates the principle of least data in reports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sanitize the data by redacting or replacing with placeholders.
Why this is correct
Sanitization preserves the evidentiary value of the finding while removing or masking the most sensitive components, such as live credentials, PII, or PHI. Replacing real values with clearly labeled placeholders (e.g., username: <REDACTED>, token: [removed]) keeps the report useful for remediation and satisfies data minimization principles, significantly lowering the impact if the report is misplaced or intercepted.
- ✗
Destroy all copies of sensitive data after the test and do not include any.
Why it's wrong here
Permanently destroying all copies and omitting any evidence is overcorrecting: the client typically needs the details to validate the finding, prioritize fixes, and meet compliance or insurance requirements. Moreover, an outright deletion may break chain-of-custody expectations and make it impossible to differentiate a real finding from a false positive, so a sanitized version that retains the essential proof is the professional approach.
- ✗
Present the data only in the oral debrief, not in written form.
Why it's wrong here
An oral debrief is ephemeral: it cannot be referenced later, leaves no audit trail for the client's management or auditors, and is subject to misinterpretation or memory loss. Written documentation is the formal deliverable that supports reproducibility, legal accountability, and contractual reporting obligations, so limiting presentation to spoken words would undermine the report's credibility and usefulness.
- ✗
Include the raw data in an encrypted appendix for the technical team.
Why it's wrong here
Encrypting raw sensitive data in an appendix still needlessly expands the attack surface, because the data remains in cleartext-equivalent form if the encryption key is compromised, and it may violate data protection regulations or the client's own policies. The technical team can act on sanitized values like hashed or tokenized references, so retaining pristine raw data is an avoidable risk that does not align with the principle of least privilege.
Go deeper
Related to this question
Learn chapter
Mobile Application Testing
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.