mediumMultiple Choice
PT0-002 Practice Question: During a penetration test, a penetration tester…
During a penetration test, a penetration tester discovers a critical vulnerability that allows unauthenticated remote code execution on a public-facing web server. According to best practices for communication during a penetration test, what should the tester do next?
⚠ Common exam trap
PT0-003 often tests the misconception that testers should fully exploit or verify findings before reporting — the correct behavior is immediate escalation of critical findings per the rules of engagement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately notify the client of the critical finding and provide initial remediation steps.
Penetration testing best practices and most rules of engagement require immediate notification of the client when a critical vulnerability — especially unauthenticated RCE on a public-facing system — is discovered, because it represents an active, exploitable risk. Providing initial remediation guidance at the same time helps the client mitigate before the finding is weaponized. This balances the tester's duty to the client with the goal of the engagement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Immediately notify the client of the critical finding and provide initial remediation steps.
Why this is correct
Critical unauthenticated RCE on a public-facing server poses immediate business risk, so the tester should promptly notify the client contact and supply initial remediation guidance. This satisfies the stem's best-practise communication requirement: escalate critical findings immediately rather than waiting for the final report.
- ✗
Document the finding and inform the client only after verifying with a second tester.
Why it's wrong here
Waiting for a second tester to verify delays escalation of an unauthenticated RCE already confirmed on a public host, prolonging exposure. Best practise is immediate client notification. Peer verification suits ambiguous or low-impact findings where confirmation adds value.
- ✗
Wait until the end of the test to include it in the final report.
Why it's wrong here
Delaying notification leaves an unauthenticated RCE exposed on a public host for the test's duration, allowing real attackers to exploit it. Immediate escalation to the client contact is required. Final reports suit low-severity findings, not active critical exposure.
- ✗
Exploit the vulnerability to demonstrate the full impact before notifying the client.
Why it's wrong here
Exploiting further to demonstrate impact increases risk on a live public server and exceeds authorised scope without client consent. Immediate notification is required instead. Exploitation for impact demonstration suits isolated lab systems or explicitly approved, contained targets.
Go deeper
Related to this question
Learn chapter
Vulnerability Identification
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.