hardMultiple Choice
PT0-002 Practice Question: After completing a penetration test, the client's…
After completing a penetration test, the client's technical team requests the detailed raw data (e.g., scan results, exploit logs, packet captures) used to support the findings. According to best practices, which of the following should the penetration tester do?
⚠ Common exam trap
Candidates often assume the final report should include all evidence for completeness (Option A), overlooking the confidentiality and data handling risks inherent in raw, unsanitized data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide the raw data in a separate, sanitized deliverable with a data handling agreement
Raw data such as scan results, exploit logs, and packet captures often contain sensitive information like IP addresses, credentials, or system details. Best practices (e.g., PTES, NIST SP 800-115) dictate that raw data should be provided in a separate, sanitized deliverable accompanied by a data handling agreement to ensure confidentiality and proper data governance, rather than embedding it directly in the final report.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include all raw data in the appendices of the final report
Why it's wrong here
Including all raw data in the final report's appendices is risky because the final report is typically distributed to a wide audience, including non-technical stakeholders and third parties, whereas raw data may contain cleartext credentials, hash dumps, proof-of-exploit code, and internal network details. This exposure increases the likelihood of sensitive information leakage and violates data protection principles such as least privilege. Moreover, raw log files are often enormous and unformatted, making the report unwieldy and harder for technical teams to act on. Instead, raw data should be sanitized and delivered separately.
- ✓
Provide the raw data in a separate, sanitized deliverable with a data handling agreement
Why this is correct
The correct approach is to provide raw data in a separate, sanitized deliverable—such as a password-protected archive or controlled access repository—where overly sensitive artifacts are redacted before transfer. A data handling agreement is then signed to explicitly define allowed uses, retention periods, and disposal steps, ensuring the client can use the data for remediation and compliance while keeping confidentiality intact. This gives the client the evidence they need without turning the final report into a liability.
- ✗
Refuse to provide raw data to protect the confidentiality of the testing process
Why it's wrong here
Refusing to provide raw data is unprofessional and shortsighted because the client has a legitimate need for that raw data to verify findings, track remediation, or satisfy audit and regulatory requirements such as PCI DSS or ISO 27001. A penetration test engagement is a collaborative exercise; a flat refusal forces the client to rely solely on the report's interpretation and can erode trust in the testing process. Potential confidentiality concerns are better addressed through controlled delivery mechanisms and agreements, not by withholding the data entirely.
- ✗
Provide the raw data only if the client signs a non-disclosure agreement
Why it's wrong here
Having the client sign only a non-disclosure agreement is insufficient because an NDA merely prevents public disclosure and does not define how the raw data may be used, who has access to it, how long it can be retained, or how it must be destroyed after the engagement. Without a data handling agreement, the client might retain raw data indefinitely or misuse it in ways that conflict with the tester's obligations, creating residual risk. A proper DHA, combined with sanitization, gives enforceable parameters beyond confidentiality.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.