PT0-002 Engagement Management Practice Question
During a penetration test, the tester discovers evidence of an ongoing data breach that appears to involve criminal activity unrelated to the test scope. What is the tester's primary responsibility regarding this discovery?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Notify the client's emergency contact and follow the agreed-upon incident response procedures
The tester should follow the incident response plan and notify the client immediately, as handling criminal activity is a legal and ethical obligation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Continue the test as planned and include the findings in the final report
Why it's wrong here
Continuing the test as planned while possessing evidence of criminal activity violates the fundamental incident-handling principle that certain findings require immediate escalation, not deferred reporting. The Rules of Engagement (RoE) typically specify a mandatory notification trigger for illegal content or acts, and postponing that notification until the final report could allow ongoing harm or the destruction of forensic evidence. Moreover, the tester's continued activity might contaminate the crime scene, jeopardizing any subsequent legal investigation and potentially exposing the tester or client to liability for failure to act.
- ✓
Notify the client's emergency contact and follow the agreed-upon incident response procedures
Why this is correct
This is the correct action because a penetration test is executed under a contractual RoE that defines an explicit escalation path for exceptional findings. The tester must activate the client's named emergency contact and follow the incident response procedures to preserve evidence, contain the situation, and coordinate any law enforcement referral through the client's legal counsel. This approach balances the tester's legal duty to report criminal activity with the client's ownership of the systems and their authority to control external communications, ensuring the response is both lawful and consistent with the engagement's scope.
- ✗
Document the evidence and destroy it after the engagement to protect the client
Why it's wrong here
Destroying evidence after documenting it is a severe breach of forensic best practices and legal obligations, as it destroys any potential chain of custody and renders the evidence inadmissible in court. A penetration tester's role includes preserving artifacts that may be relevant to criminal investigations, not unilaterally deciding to dispose of them. Furthermore, such destruction could constitute spoliation, exposing the test firm and client to legal penalties and damaging the client's ability to pursue remediation or prosecution, so the only proper course is to secure and hand over the evidence intact.
- ✗
Immediately stop testing and notify law enforcement without client approval
Why it's wrong here
Unilaterally stopping the test and contacting law enforcement bypasses the client's authority and the agreed-upon incident response framework, potentially breaching confidentiality and the RoE. In a penetration test, the client is the legal owner of the environment and the party entitled to make decisions about external notifications, especially since apparent 'criminal' activity could, in some cases, be a previously authorized test component or a false positive. The tester should instead escalate through the designated emergency contact, allowing the client's incident response team to verify the finding, preserve evidence, and engage law enforcement through proper legal channels while maintaining chain of custody.
Go deeper
Related to this question
Learn chapter
Writing Penetration Test Reports
Key term
Evidence
Evidence is any data or documentation that proves an event, action, or condition occurred, crucial for verifying compliance, security incidents, or system changes.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.