Courseiva
hardMultiple Choice

PT0-002 Practice Question: During a penetration test, the tester discovers…

During a penetration test, the tester discovers evidence that an external attacker is actively exploiting a vulnerability in the client's environment. Which of the following is the MOST appropriate action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately notify the client and stop testing

If there is evidence of a live attack or criminal activity, the tester should stop testing and immediately notify the client so they can take appropriate action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Document the evidence and ignore it

    Why it's wrong here

    Recording the evidence without escalating leaves the client's network actively compromised while the tester passively observes, violating the core incident-response duty to minimize harm. In a live-attack scenario, the tester's obligation shifts from assessment to responsible disclosure, and ignoring the activity could allow data exfiltration or lateral movement to continue unchecked.

  • ✗

    Attempt to block the attacker's activities

    Why it's wrong here

    Taking defensive actions such as blocking IPs or terminating processes exceeds the penetration test's scope and can disrupt the attacker's activities, destroying forensic evidence and potentially causing unintended denial-of-service to client systems. Furthermore, the tester lacks authority to make incident-response decisions; only the client's designated response team should contain the threat, and the tester's role is to report and stand down.

  • ✓

    Immediately notify the client and stop testing

    Why this is correct

    When evidence indicates an ongoing attack, the tester must immediately stop testing to avoid compounding the incident and notify the client so they can activate their incident response plan. Continuing to test could interfere with forensic preservation or accidentally interact with the attacker's C2 infrastructure, so halting all intrusive actions and delivering a clear, time-sensitive briefing is the only defensible course.

  • ✗

    Continue testing and include the finding in the final report

    Why it's wrong here

    Deferring notification to a final report leaves the client blind to an active compromise, enabling the attacker to persist and potentially spread while the engagement continues. The final report is a post-engagement artifact; a live attack demands real-time escalation, so waiting not only violates incident-handling norms but also exposes the tester to legal and ethical liability for damages incurred during the delay.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.