PT0-002 Engagement Management Practice Question
A penetration tester is preparing a proposal for a client. The client wants a test that includes a detailed technical report with remediation steps and an executive summary for management. Which standard or framework is most commonly used to structure the testing process from pre-engagement through post-engagement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PTES
The Penetration Testing Execution Standard (PTES) provides a comprehensive framework covering all phases from pre-engagement to post-engagement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OWASP Testing Guide
Why it's wrong here
The OWASP Testing Guide is a specialized resource focused exclusively on web application security testing, providing detailed test cases for vulnerabilities like injection, broken authentication, and XSS. While it is invaluable during the web application testing phase, it does not address the full engagement lifecycle—missing critical components such as pre-engagement scoping, rules of engagement, threat modeling, exploitation outside web contexts, and structured post-engagement reporting. Thus, it is unsuitable as the overarching methodology for a general penetration testing proposal.
- ✗
OSSTMM
Why it's wrong here
The OSSTMM (Open Source Security Testing Methodology Manual) is a peer-reviewed methodology that emphasizes verification and operational security metrics, such as the Risk Assessment Values (RAVs), rather than a linear engagement lifecycle. It is more aligned with security audits and compliance verification than with offensive penetration testing, and it lacks explicit, prescriptive phases for pre-engagement intelligence gathering, exploitation, post-exploitation, and tailored client reporting. Consequently, while it is a legitimate security testing methodology, it is not the industry-standard choice for a full engagement structure in a typical commercial pentest proposal.
- ✓
PTES
Why this is correct
PTES (Penetration Testing Execution Standard) is the correct choice because it defines a comprehensive, industry-recognized framework covering all seven phases of a penetration test: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This structure is specifically designed for professional penetration testing engagements, ensuring that legal boundaries are established, scoping is thorough, and deliverables are actionable and client-focused. Its widespread adoption and practical focus make it the most suitable methodology to cite in a proposal promising a full, end-to-end penetration test.
- ✗
NIST SP 800-115
Why it's wrong here
NIST SP 800-115 is a technical guide that describes testing techniques (e.g., network discovery, vulnerability scanning, password cracking) and provides implementation guidance for security assessments. However, it does not prescribe a structured engagement methodology with formal phases for pre-engagement negotiation, threat modeling, or post-engagement reporting, and it is not as widely adopted as a commercial pentest framework. It is often used by federal agencies as a reference for technical testing activities, but it is insufficient for a client proposal that requires a clearly scoped, legally sound, and comprehensive penetration testing process.
Go deeper
Related to this question
Learn chapter
Post-Exploitation Techniques
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.