Courseiva
mediumMultiple Choice

PT0-002 Practice Question: During a penetration test, the tester discovers…

During a penetration test, the tester discovers evidence of an ongoing cyber attack by an external threat actor on the client's network. What is the tester's responsibility?

⚠ Common exam trap

A common mix-up: candidates confuse the tester's role with that of a law enforcement officer or incident responder, incorrectly believing they should investigate or engage the attacker, when in fact the tester must stop all testing and immediately notify the client.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately report the evidence to the client and recommend involving law enforcement.

The tester's primary responsibility is to protect the client's assets and data. Upon discovering evidence of an ongoing cyber attack, immediate notification allows the client to activate incident response procedures, potentially containing the threat and minimizing damage. Recommending law enforcement involvement is appropriate when criminal activity is suspected, as the tester is not authorized to conduct forensic investigation or engage with the attacker.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Document the evidence and include it in the final report without immediate notification.

    Why it's wrong here

    Documenting the evidence and deferring action until the final report violates the tester’s duty to protect the client. An active compromise presents immediate risk to confidentiality, integrity, and availability, and incident response requires real-time notification so the client can isolate affected systems and preserve volatile evidence. By the time the final report is delivered, additional data may be lost, and the client could be legally liable for failing to disclose a breach. The tester should escalate to the client’s incident response team or emergency contact as soon as an unauthorized attacker is identified.

  • ✗

    Attempt to trace and engage the attacker to gather more information.

    Why it's wrong here

    Attempting to trace or engage the attacker is not only dangerous but also falls outside the approved penetration test scope and may violate laws such as the Computer Fraud and Abuse Act (CFAA) or equivalent regulations. Such actions could trigger a counterattack, destroy evidence, or tip off the attacker, making the investigation harder for law enforcement. The tester's authorization is limited to the host and networks specified in the contract; actively interacting with an external threat actor goes beyond that. The proper response is to alert the client and let trained incident responders and law enforcement conduct the investigation.

  • ✓

    Immediately report the evidence to the client and recommend involving law enforcement.

    Why this is correct

    Immediately reporting the evidence to the client and recommending law enforcement is the only appropriate response once an active threat is discovered. This action aligns with the tester's ethical and contractual obligation to protect the client's interests and enables timely incident response, including containing the attack and preserving forensically sound evidence. Recommending law enforcement is crucial because the attacker is committing a crime, and the evidence collected may be admissible in court if chain of custody is maintained. The tester should also document all subsequent actions and communications to support the investigation.

  • ✗

    Ignore the evidence and continue with the planned test scope.

    Why it's wrong here

    Ignoring evidence of an ongoing attack and continuing the planned test is a severe professional failure that could have disastrous consequences. An active attacker is a critical vulnerability that outranks any test objective, and proceeding with the test could conflate your actions with the attacker's, undermining the validity of the results. Moreover, the tester has a legal and ethical obligation to act in the client's best interest, which requires immediate escalation of any discovered threat. Halting the test and reporting is the only way to avoid contributing to further compromise.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.