hardMultiple Select
PT0-002 Practice Question: A penetration tester is handling a client's…
A penetration tester is handling a client's pushback on a finding. Which THREE approaches are appropriate? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Re-evaluate the finding and adjust if new information is available
When handling pushback, the tester should listen, provide evidence, and possibly adjust the report if valid points are made.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Re-evaluate the finding and adjust if new information is available
Why this is correct
Re-evaluating a finding when new information is presented aligns with the fundamental principle of evidence-based penetration testing. The tester should treat each finding as a hypothesis that is validated by both technical proof and environmental context; if the client provides new facts—such as a compensating control, a patched system, or an architectural detail that alters exploitability—the severity and validity must be updated accordingly. This is not capitulation but professional diligence, ensuring the report accurately reflects the client's true risk posture.
- ✓
Provide additional evidence to support the finding
Why this is correct
Supplementing the report with additional, concrete evidence can directly counter client pushback by demonstrating that the finding is not a theoretical claim but a reproducible issue. Examples include packet captures, proof-of-concept screenshots, the exact command sequence used, a CVSS vector breakdown, and an analysis of how a compromised asset could be leveraged laterally. This approach shifts the conversation from subjective disagreement to objective technical facts, helping the client understand the real-world exploitability and business impact.
- ✗
Immediately lower the severity to satisfy the client
Why it's wrong here
Severity ratings must be grounded in objective risk factors such as exploitability, impact, asset criticality, and the effectiveness of existing controls—not in client satisfaction or pressure. Immediately lowering severity to satisfy the client is ethically dubious and operationally dangerous, as it can leave a critical vulnerability unresolved and expose the client to financial, legal, and reputational harm. A professional pentester must maintain independence and stand by well-supported risk assessments while remaining open to re-validation if new evidence emerges.
- ✓
Listen to the client's concerns and discuss them
Why this is correct
Listening to the client's concerns is a critical communication skill in penetration testing because the client often has knowledge of compensating controls, business context, or recent changes that the tester did not observe during the assessment. An open discussion allows the tester to capture that additional context, verify it against the evidence, and potentially revise the finding if a true false positive is identified. It also builds trust and demonstrates that the tester values the client's perspective rather than treating the report as an unassailable verdict.
- ✗
Refuse to change the report under any circumstances
Why it's wrong here
Refusing to change the report under any circumstances is misguided because new information can legitimately invalidate or refine a finding, and a blanket refusal would violate the tester's obligation to provide an accurate final report. However, this does not mean succumbing to pressure; any change should be based on re-testing and confirmed evidence. This option is wrong specifically because it ignores the possibility that the client might have valid, material facts that warrant an adjustment, while also failing to distinguish between inappropriate pressure and legitimate new data.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.