Courseiva
mediumMultiple Choice

PT0-002 Practice Question: During a penetration test, a tester discovers a…

During a penetration test, a tester discovers a critical vulnerability that could allow remote code execution on an internet-facing server. According to best practices, what is the most appropriate immediate action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Notify the client immediately about the critical finding.

Critical findings should be communicated immediately so the client can take urgent action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Keep the finding confidential until retesting.

    Why it's wrong here

    Holding a critical finding confidential until a retest is flawed because the retest occurs only after remediation, so this approach needlessly delays the remediation start. It also confuses internal project communication with public disclosure: you are expected to share the vulnerability with the client's security team immediately, not hide it until a later validation pass. This increases the window of exploitation and violates the core purpose of a penetration test, which is to inform the client of risks in time to act.

  • ✓

    Notify the client immediately about the critical finding.

    Why this is correct

    Notifying the client immediately about a critical finding is correct because critical vulnerabilities—such as remote code execution, authentication bypass, or SQL injection with data access—represent an imminent and material risk to the organization. Prompt communication enables the client to initiate emergency incident response, apply temporary mitigations, or patch the affected system before the final report is delivered. This practice is usually mandated by the rules of engagement and aligns with professional standards that prioritize minimizing exposure over adhering to a rigid reporting schedule.

  • ✗

    Exploit the vulnerability to demonstrate impact.

    Why it's wrong here

    Exploiting remote code execution risks disrupting a production internet-facing server and exceeds the agreed scope, whereas best practice is to stop, document evidence and report to the client immediately. Exploitation is appropriate only when the rules of engagement explicitly authorise it and a safe test environment exists.

  • ✗

    Wait until the final report to disclose the finding.

    Why it's wrong here

    Waiting until the final report to disclose a critical finding is dangerous because the elapsed time between discovery and delivery can be days or weeks, during which attackers could exploit the vulnerability. The purpose of a final report is to provide comprehensive documentation, metrics, and remediation guidance, but it is not a substitute for time-sensitive notification. Real-world penetration testing standards, such as those from PTES or OWASP, recommend immediate notification for critical or high-risk issues to give the client the earliest possible chance to reduce risk.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.