Courseiva
mediumMultiple Choice

PT0-002 Practice Question: During a penetration test, the tester discovers…

During a penetration test, the tester discovers active ransomware on a critical server. Which communication should the tester perform FIRST according to standard rules of engagement?

⚠ Common exam trap

CompTIA often tests the misconception that a penetration tester should attempt to contain or remediate active threats, but the correct action is always to notify the client's emergency contact immediately, as testers are observers, not incident responders.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately notify the client's emergency contact

The standard rules of engagement (ROE) for penetration testing require immediate notification of the client's emergency contact upon discovery of active ransomware. This is because ransomware represents an active, ongoing security incident that demands urgent response to prevent data loss and further spread, overriding the normal testing timeline. The tester must not attempt containment or continue testing, as those actions could interfere with incident response or violate legal boundaries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Include it in the final report

    Why it's wrong here

    Delaying notification until the final report violates the fundamental incident-response principle that time-to-detection is critical; ransomware propagation can reach irreversible levels (e.g., encryption of backups, lateral movement) within minutes. Your engagement's reporting requirements almost certainly mandate immediate escalation of any active compromise, not just a write-up at the end. In practice, this delay could be deemed negligent and damage your professional reputation.

  • ✓

    Immediately notify the client's emergency contact

    Why this is correct

    The emergency contact is the predefined channel for urgent, time-sensitive findings, and notifying them immediately triggers their incident-response process, enables isolation of affected systems, and starts preservation of forensic evidence. This aligns with the core pen-test rule: you are to report, not remediate, and you should never assume you have the client's authority to take active defensive action. Acting promptly also covers your legal and ethical duty to prevent further harm, which is the primary reason this is the only correct choice.

  • ✗

    Attempt to contain the ransomware

    Why it's wrong here

    Attempting to contain the ransomware—such as killing processes, disconnecting hosts, or rolling back changes—exceeds the tester's authorization and commonly violates the rules of engagement (RoE) that limit actions to those explicitly permitted. Even well-intentioned containment could destroy volatile evidence, trigger the ransomware's anti-forensics or self-destruction mechanisms, or inadvertently disconnect critical production systems. You also lack the client's incident-response procedures and tools, so your actions might contradict their official playbook and create legal liability.

  • ✗

    Log the finding and continue testing

    Why it's wrong here

    Continuing the penetration test after discovering an active ransomware infection is both unethical and operationally reckless, as your subsequent exploitation attempts could interact with the ransomware and accelerate its spread or trigger destructive payloads. The tester's duty of care to the client outweighs any desire to complete the test, and staying quiet while the threat persists constitutes negligence. You must not proceed until the incident is handled, because your authorized testing window is suspended during any live emergency response.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.