PT0-002 Engagement Management Practice Question
During a penetration test, the tester discovers evidence of an ongoing criminal activity, such as unauthorized data exfiltration by an insider. The client's legal team has not provided specific guidance on handling such discoveries. According to best practices and legal considerations, what should the tester do first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stop testing and report the finding to the client immediately
The correct option is D: stop testing and report the finding to the client immediately. In penetration testing, when evidence of ongoing criminal activity such as unauthorized data exfiltration by an insider is discovered and the client's legal team has not provided specific guidance, the tester's first duty is to halt testing and notify the client so their legal counsel can decide how to proceed, preserving evidence and avoiding interference with a potential investigation. Continuing testing (A) risks destroying evidence or tipping off the insider, and contacting law enforcement directly (B) bypasses the client's authority and could violate the engagement contract or legal privilege. Ignoring the finding (C) is unethical and potentially illegal, as it conceals known criminal activity rather than escalating it through the proper client channel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Continue testing to gather more evidence
Why it's wrong here
Continued testing risks destroying or altering evidence and delays the client's legal notification obligations. Gathering further proof is tempting because penetration testers habitually validate findings before reporting, and it would be right when confirming an ordinary vulnerability that carries no legal disclosure duty.
- ✗
Contact law enforcement directly
Why it's wrong here
The tester is not the data owner and cannot report the incident on the client's behalf; premature external disclosure breaches confidentiality and may compromise the client's own regulatory or law-enforcement strategy. Contacting authorities is tempting because it feels responsible, and would be correct if the client's legal team directed it.
- ✗
Ignore the finding as it is out of scope
Why it's wrong here
Scope governs authorisation to test, not the duty to report suspected criminal activity encountered incidentally; suppressing it exposes the tester and client to liability. Ignoring out-of-scope findings is tempting because scope discipline is drilled into testers, and would be right for unrelated technical issues with no legal consequence.
- ✓
Stop testing and report the finding to the client immediately
Why this is correct
Evidence of ongoing criminal activity triggers a legal and ethical duty that overrides the engagement scope. Halting testing preserves evidence integrity and prevents further harm, while immediate notification lets the client's legal team direct next steps, satisfying the requirement to act without specific prior guidance.
Go deeper
Related to this question
Learn chapter
PowerShell for Penetration Testing
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Evidence
Evidence is any data or documentation that proves an event, action, or condition occurred, crucial for verifying compliance, security incidents, or system changes.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.