Courseiva
mediumMultiple Choice

PT0-002 Practice Question: During a penetration test, the tester discovers…

During a penetration test, the tester discovers that a third-party vendor has remote access to the client's network. The vendor was not mentioned in the scope of work. How should the tester communicate this finding in the report?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document it in the 'Observations' or 'Out-of-Scope Findings' section.

The correct option is B: Document it in the 'Observations' or 'Out-of-Scope Findings' section. Even though the third-party vendor's remote access was not in the scope of work, it is a relevant security-relevant discovery that the client should know about, and standard penetration testing reporting practices (e.g., PTES, OWASP Testing Guide) provide an out-of-scope or observations section for exactly such items. This preserves the integrity of the agreed scope while still delivering value to the client. Option A is wrong because ignoring a discovered risk is unprofessional and could harm the client. Option C is wrong because it was not tested or validated as a vulnerability, so labeling it critical in the main findings would misrepresent the engagement. Option D is wrong because removing the finding entirely withholds potentially important information from the client.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ignore it entirely because it is outside the testing agreement.

    Why it's wrong here

    Ignoring the vendor's remote access discards a genuine security-relevant observation simply because it was untested. Scope restricts what the tester may attack, not what they may report. The correct approach documents it in an out-of-scope or informational section for the client to investigate and address.

  • ✓

    Document it in the 'Observations' or 'Out-of-Scope Findings' section.

    Why this is correct

    The vendor's remote access sits outside the agreed scope, so it must not be presented as an in-scope vulnerability. Recording it under Observations or Out-of-Scope Findings preserves the evidence for the client while keeping the formal findings aligned to the authorised scope of work.

  • ✗

    Include it as a critical vulnerability in the main findings.

    Why it's wrong here

    An unlisted vendor with remote access is a scope and governance observation, not a tested exploitable weakness, so it does not belong in main findings as a critical vulnerability. It is tempting because unauthorised access sounds severe. It belongs in a separate section noting out-of-scope discoveries for the client to investigate.

  • ✗

    Remove the finding because it is out of scope.

    Why it's wrong here

    Deleting the finding withholds information the client needs about an unknown third party holding remote access to their network. Scope limits testing actions, not reporting of observations. The correct approach records it in a dedicated out-of-scope or informational section so the client can investigate and update the agreement.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.