Courseiva
Engagement Management →mediumMultiple Choice

PT0-002 Engagement Management Practice Question

A penetration tester is preparing a proposal for a client. The client wants a test that includes a detailed technical report with remediation steps and an executive summary for management. Which standard or framework is most commonly used to structure the testing process from pre-engagement through post-engagement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PTES

The Penetration Testing Execution Standard (PTES) provides a comprehensive framework covering all phases from pre-engagement to post-engagement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    OWASP Testing Guide

    Why it's wrong here

    The OWASP Testing Guide is a specialized resource focused exclusively on web application security testing, providing detailed test cases for vulnerabilities like injection, broken authentication, and XSS. While it is invaluable during the web application testing phase, it does not address the full engagement lifecycle—missing critical components such as pre-engagement scoping, rules of engagement, threat modeling, exploitation outside web contexts, and structured post-engagement reporting. Thus, it is unsuitable as the overarching methodology for a general penetration testing proposal.

  • ✗

    OSSTMM

    Why it's wrong here

    The OSSTMM (Open Source Security Testing Methodology Manual) is a peer-reviewed methodology that emphasizes verification and operational security metrics, such as the Risk Assessment Values (RAVs), rather than a linear engagement lifecycle. It is more aligned with security audits and compliance verification than with offensive penetration testing, and it lacks explicit, prescriptive phases for pre-engagement intelligence gathering, exploitation, post-exploitation, and tailored client reporting. Consequently, while it is a legitimate security testing methodology, it is not the industry-standard choice for a full engagement structure in a typical commercial pentest proposal.

  • ✓

    PTES

    Why this is correct

    PTES (Penetration Testing Execution Standard) is the correct choice because it defines a comprehensive, industry-recognized framework covering all seven phases of a penetration test: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This structure is specifically designed for professional penetration testing engagements, ensuring that legal boundaries are established, scoping is thorough, and deliverables are actionable and client-focused. Its widespread adoption and practical focus make it the most suitable methodology to cite in a proposal promising a full, end-to-end penetration test.

  • ✗

    NIST SP 800-115

    Why it's wrong here

    NIST SP 800-115 is a technical guide that describes testing techniques (e.g., network discovery, vulnerability scanning, password cracking) and provides implementation guidance for security assessments. However, it does not prescribe a structured engagement methodology with formal phases for pre-engagement negotiation, threat modeling, or post-engagement reporting, and it is not as widely adopted as a commercial pentest framework. It is often used by federal agencies as a reference for technical testing activities, but it is insufficient for a client proposal that requires a clearly scoped, legally sound, and comprehensive penetration testing process.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.