Courseiva
Engagement Management →hardMultiple Choice

PT0-002 Engagement Management Practice Question

During a penetration test, the tester discovers evidence of an ongoing criminal activity, such as unauthorized data exfiltration by an insider. The client's legal team has not provided specific guidance on handling such discoveries. According to best practices and legal considerations, what should the tester do first?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Stop testing and report the finding to the client immediately

The correct option is D: stop testing and report the finding to the client immediately. In penetration testing, when evidence of ongoing criminal activity such as unauthorized data exfiltration by an insider is discovered and the client's legal team has not provided specific guidance, the tester's first duty is to halt testing and notify the client so their legal counsel can decide how to proceed, preserving evidence and avoiding interference with a potential investigation. Continuing testing (A) risks destroying evidence or tipping off the insider, and contacting law enforcement directly (B) bypasses the client's authority and could violate the engagement contract or legal privilege. Ignoring the finding (C) is unethical and potentially illegal, as it conceals known criminal activity rather than escalating it through the proper client channel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Continue testing to gather more evidence

    Why it's wrong here

    Continued testing risks destroying or altering evidence and delays the client's legal notification obligations. Gathering further proof is tempting because penetration testers habitually validate findings before reporting, and it would be right when confirming an ordinary vulnerability that carries no legal disclosure duty.

  • ✗

    Contact law enforcement directly

    Why it's wrong here

    The tester is not the data owner and cannot report the incident on the client's behalf; premature external disclosure breaches confidentiality and may compromise the client's own regulatory or law-enforcement strategy. Contacting authorities is tempting because it feels responsible, and would be correct if the client's legal team directed it.

  • ✗

    Ignore the finding as it is out of scope

    Why it's wrong here

    Scope governs authorisation to test, not the duty to report suspected criminal activity encountered incidentally; suppressing it exposes the tester and client to liability. Ignoring out-of-scope findings is tempting because scope discipline is drilled into testers, and would be right for unrelated technical issues with no legal consequence.

  • ✓

    Stop testing and report the finding to the client immediately

    Why this is correct

    Evidence of ongoing criminal activity triggers a legal and ethical duty that overrides the engagement scope. Halting testing preserves evidence integrity and prevents further harm, while immediate notification lets the client's legal team direct next steps, satisfying the requirement to act without specific prior guidance.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.