mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is preparing a report and…
A penetration tester is preparing a report and wants to include proof-of-concept code to demonstrate a vulnerability. Which of the following is the best practice for including such code?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide code that demonstrates the vulnerability in a responsible manner without destructive payloads.
Proof-of-concept code should prove the vulnerability is exploitable without causing harm to the client's environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include fully automated exploit scripts that could be used for attacks.
Why it's wrong here
Including fully automated exploit scripts, such as a complete Metasploit module or a one-click reverse shell, in a penetration test report is inappropriate because it lowers the skill barrier to re-exploitation. A fully automated script can be run by anyone with little technical knowledge, turning the report into a weapon rather than a diagnostic artifact. The goal of a report is to demonstrate the flaw and its remediation, not to provide a turnkey attack tool that adversaries could misuse even if the report is leaked.
- ✗
Include code that extracts sensitive data to prove impact.
Why it's wrong here
Including code that extracts sensitive data, such as a SQL injection payload that dumps actual customer records or a script that reads local files, is both harmful and unethical. Running such code during the test may violate data protection laws, client agreements, or the principle of least privilege, and including it in the report normalizes handling real data without need. The impact of a vulnerability can be proven with synthetic or dummy data, or by demonstrating the mechanism of extraction without actually pulling live sensitive content.
- ✓
Provide code that demonstrates the vulnerability in a responsible manner without destructive payloads.
Why this is correct
Providing code that demonstrates the vulnerability in a responsible manner is the correct approach because it gives the client concrete, reproducible proof of the flaw without enabling real damage. A responsible proof-of-concept might use a benign payload, such as a crafted HTTP request that returns an error message indicating SQL injection, or a script that triggers a 200 vs 500 response to show an access control issue. This balances the need for evidence with the ethics of disclosure, allowing developers to reproduce and fix the issue without causing data loss or system compromise.
- ✗
Omit code and only describe the vulnerability verbally.
Why it's wrong here
Omitting code entirely and only verbally describing the vulnerability is insufficient for a professional penetration test report because code provides the concrete, reproducible evidence needed for developers to independently verify and fix the issue. A verbal description alone can be vague or misinterpreted, and the client cannot easily validate the finding or track its remediation. While the text should not include fully weaponized exploit code, a minimal, non-destructive snippet or request example is essential for a credible and actionable report.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.