Courseiva
mediumMultiple Select

PT0-002 Practice Question: A penetration tester is following responsible…

A penetration tester is following responsible disclosure timelines. Which TWO of the following actions align with responsible disclosure practices?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Notify the software vendor immediately after discovery.

Responsible disclosure involves notifying the vendor and providing a reasonable time to fix before public disclosure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Publish exploit code on a public forum immediately.

    Why it's wrong here

    Publishing exploit code on a public forum immediately weaponizes the vulnerability before any patch exists. A working proof-of-concept (PoC) lowers the skill barrier, allowing even unskilled attackers to compromise affected systems at scale. This also ignores the vendor's need to develop and test a fix, and may expose the tester to legal liability under laws such as the CFAA or vendor-specific anti-circumvention clauses.

  • ✗

    Publicly disclose the vulnerability the same day.

    Why it's wrong here

    Publicly disclosing the vulnerability on the same day reveals critical technical details—such as affected code paths or attack vectors—to the entire threat landscape before the vendor has even acknowledged the issue. Unlike a private vendor notification, same-day disclosure effectively issues a zero-day advisory to attackers and defenders simultaneously, giving malicious actors a head start to develop exploits while users remain defenseless. This violates the core tenet of responsible disclosure: give the vendor time to remediate before making details public.

  • ✓

    Notify the software vendor immediately after discovery.

    Why this is correct

    Notifying the software vendor immediately after discovery initiates the coordinated disclosure process, which is the industry-standard first step. The vendor can reproduce the vulnerability, identify affected versions, and begin developing a patch or workaround in a controlled environment. Early notification also allows the vendor to request a CVE identifier and prepare security advisories, ensuring that when details are finally public, mitigations are already available.

  • ✗

    Sell the vulnerability information to the highest bidder.

    Why it's wrong here

    Selling vulnerability information to the highest bidder typically routes the details to exploit brokers, state-sponsored actors, or criminal groups rather than the vendor or users. This action converts a security flaw into a commercial weapon, depriving the vendor of the opportunity to patch and potentially leading to months of undetected exploitation. It is both unethical and often illegal, as many jurisdictions treat such sales as trafficking in cyberweapons or fraudulent behavior.

  • ✓

    Allow the vendor a reasonable timeframe to patch.

    Why this is correct

    Allowing the vendor a reasonable timeframe to patch is the second half of responsible disclosure and complements the immediate notification. Typical coordinated disclosure windows are 90 days, during which the vendor can develop, test, and release a fix without external pressure. This practice also lets the tester verify the patch's effectiveness, ensures mitigations are documented in the advisory, and avoids the public panic or rushed workarounds that premature disclosure can cause.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.