Courseiva
hardMultiple Choice

PT0-002 Practice Question: During a penetration test, the tester discovers…

During a penetration test, the tester discovers evidence of an ongoing ransomware attack on the client's network. Which of the following is the most appropriate action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Notify the client immediately and recommend contacting law enforcement.

Evidence of criminal activity must be reported immediately to the client and may require law enforcement involvement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Continue the test as planned and include the finding in the final report.

    Why it's wrong here

    Continuing the test as planned while knowing an active ransomware infection is underway prioritizes test objectives over the client's immediate safety. This violates the pentester's ethical duty to minimize harm and conflicts with the rules of engagement, which typically require stopping all activity when a critical incident is discovered. Delaying notification gives the ransomware time to propagate, encrypt more systems, and expand the blast radius, potentially turning a contained incident into a full-scale breach. Even a well-documented final report cannot undo the damage caused by that delay.

  • ✓

    Notify the client immediately and recommend contacting law enforcement.

    Why this is correct

    Immediate notification is the only correct action because ransomware is an active criminal incident that requires instantaneous incident response, not a passive test finding. As a penetration tester, you have no authority to remediate or direct law enforcement, but you do have a contractual and ethical obligation to alert the client's designated contacts so they can initiate containment and recovery. Recommending law enforcement is appropriate because ransomware is a crime, and involving police ensures proper evidence preservation, legal handling, and potential attribution. This action aligns with industry standards such as those from PTES and NIST, which dictate that suspected criminal activity discovered during a test must be reported immediately to the client.

  • ✗

    Disconnect from the network and destroy all evidence.

    Why it's wrong here

    Disconnecting from the network and destroying evidence is both illegal and counterproductive to any subsequent forensic investigation. Tampering with or destroying evidence can constitute obstruction of justice, exposing the tester to criminal liability, and it irrevocably destroys the digital artifacts needed to identify the attack vector and recover encrypted data. Furthermore, the decision to disconnect a system should be made by the client's incident response team, as abruptly severing network connectivity can trigger additional harm or eliminate the ability to observe the attacker's behavior. The tester's role is to preserve evidence and report, never to unilaterally alter or erase it.

  • ✗

    Try to stop the ransomware attack using penetration testing tools.

    Why it's wrong here

    Attempting to stop the ransomware with penetration testing tools exceeds the scope of the engagement and violates the fundamental boundary between testing and remediation. The tester is not authorized to take corrective action, and using tools to interfere with an active attack could cause unintended damage, such as disrupting recovery efforts or triggering anti-forensic mechanisms. Moreover, the tester likely lacks the tools and expertise to safely neutralize ransomware, and any active countermeasures could complicate later legal proceedings or void insurance coverage. The correct approach is to notify the client and law enforcement, who have the authority and capability to respond.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.