Courseiva
Engagement Management →mediumMultiple Choice

PT0-002 Engagement Management Practice Question

During a penetration test, the tester discovers evidence of an ongoing data breach that appears to involve criminal activity unrelated to the test scope. What is the tester's primary responsibility regarding this discovery?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Notify the client's emergency contact and follow the agreed-upon incident response procedures

The tester should follow the incident response plan and notify the client immediately, as handling criminal activity is a legal and ethical obligation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Continue the test as planned and include the findings in the final report

    Why it's wrong here

    Continuing the test as planned while possessing evidence of criminal activity violates the fundamental incident-handling principle that certain findings require immediate escalation, not deferred reporting. The Rules of Engagement (RoE) typically specify a mandatory notification trigger for illegal content or acts, and postponing that notification until the final report could allow ongoing harm or the destruction of forensic evidence. Moreover, the tester's continued activity might contaminate the crime scene, jeopardizing any subsequent legal investigation and potentially exposing the tester or client to liability for failure to act.

  • ✓

    Notify the client's emergency contact and follow the agreed-upon incident response procedures

    Why this is correct

    This is the correct action because a penetration test is executed under a contractual RoE that defines an explicit escalation path for exceptional findings. The tester must activate the client's named emergency contact and follow the incident response procedures to preserve evidence, contain the situation, and coordinate any law enforcement referral through the client's legal counsel. This approach balances the tester's legal duty to report criminal activity with the client's ownership of the systems and their authority to control external communications, ensuring the response is both lawful and consistent with the engagement's scope.

  • ✗

    Document the evidence and destroy it after the engagement to protect the client

    Why it's wrong here

    Destroying evidence after documenting it is a severe breach of forensic best practices and legal obligations, as it destroys any potential chain of custody and renders the evidence inadmissible in court. A penetration tester's role includes preserving artifacts that may be relevant to criminal investigations, not unilaterally deciding to dispose of them. Furthermore, such destruction could constitute spoliation, exposing the test firm and client to legal penalties and damaging the client's ability to pursue remediation or prosecution, so the only proper course is to secure and hand over the evidence intact.

  • ✗

    Immediately stop testing and notify law enforcement without client approval

    Why it's wrong here

    Unilaterally stopping the test and contacting law enforcement bypasses the client's authority and the agreed-upon incident response framework, potentially breaching confidentiality and the RoE. In a penetration test, the client is the legal owner of the environment and the party entitled to make decisions about external notifications, especially since apparent 'criminal' activity could, in some cases, be a previously authorized test component or a false positive. The tester should instead escalate through the designated emergency contact, allowing the client's incident response team to verify the finding, preserve evidence, and engage law enforcement through proper legal channels while maintaining chain of custody.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.