Courseiva
hardMultiple Choice

PT0-002 Practice Question: During a penetration test, a tester discovers…

During a penetration test, a tester discovers evidence of an ongoing data exfiltration attack by an unknown third party. Which of the following should the tester do first?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately notify the client point of contact

Evidence of criminal activity should be reported immediately to the client, who can then involve law enforcement if needed. The tester should not interfere directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Contact law enforcement directly

    Why it's wrong here

    Contacting law enforcement directly bypasses the client's authority and legal decision-making role. The client owns the incident response process, including whether to involve police, and direct contact could breach confidentiality agreements, violate scope, and compromise the chain of custody for any evidence. It may also alert the adversary prematurely, jeopardizing ongoing containment efforts.

  • ✓

    Immediately notify the client point of contact

    Why this is correct

    Immediately notifying the client point of contact fulfills the tester's primary obligation during a suspected active breach. The client can then activate their incident response plan, preserve forensic evidence, and decide on involving law enforcement or other third parties. This aligns with the rules of engagement, contractual duties, and the need for timely mitigation to minimize damage.

  • ✗

    Document the evidence and include it in the final report

    Why it's wrong here

    Though documentation is essential, deferring notification until the final report significantly delays critical incident response. The client needs real-time warning to contain the exfiltration, rotate compromised credentials, and notify affected parties; waiting could allow additional data loss or worsen the breach. Documentation should be an ongoing parallel activity, not a substitute for immediate communication.

  • ✗

    Attempt to block the exfiltration to protect the client

    Why it's wrong here

    Actively attempting to block exfiltration exceeds the tester's authorization and may violate laws such as the Computer Fraud and Abuse Act. Such intervention can disrupt client operations, destroy evidence, or escalate the attacker's actions, and the tester lacks the legal authority to take defensive measures. The correct posture is to observe passively, record indicators, and report findings through the proper channel.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.