mediumMultiple Choice
PT0-002 Practice Question: During a penetration test, the tester discovers…
During a penetration test, the tester discovers that a third-party vendor has remote access to the client's network. The vendor was not mentioned in the scope of work. How should the tester communicate this finding in the report?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document it in the 'Observations' or 'Out-of-Scope Findings' section.
The correct option is B: Document it in the 'Observations' or 'Out-of-Scope Findings' section. Even though the third-party vendor's remote access was not in the scope of work, it is a relevant security-relevant discovery that the client should know about, and standard penetration testing reporting practices (e.g., PTES, OWASP Testing Guide) provide an out-of-scope or observations section for exactly such items. This preserves the integrity of the agreed scope while still delivering value to the client. Option A is wrong because ignoring a discovered risk is unprofessional and could harm the client. Option C is wrong because it was not tested or validated as a vulnerability, so labeling it critical in the main findings would misrepresent the engagement. Option D is wrong because removing the finding entirely withholds potentially important information from the client.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore it entirely because it is outside the testing agreement.
Why it's wrong here
Ignoring the vendor's remote access discards a genuine security-relevant observation simply because it was untested. Scope restricts what the tester may attack, not what they may report. The correct approach documents it in an out-of-scope or informational section for the client to investigate and address.
- ✓
Document it in the 'Observations' or 'Out-of-Scope Findings' section.
Why this is correct
The vendor's remote access sits outside the agreed scope, so it must not be presented as an in-scope vulnerability. Recording it under Observations or Out-of-Scope Findings preserves the evidence for the client while keeping the formal findings aligned to the authorised scope of work.
- ✗
Include it as a critical vulnerability in the main findings.
Why it's wrong here
An unlisted vendor with remote access is a scope and governance observation, not a tested exploitable weakness, so it does not belong in main findings as a critical vulnerability. It is tempting because unauthorised access sounds severe. It belongs in a separate section noting out-of-scope discoveries for the client to investigate.
- ✗
Remove the finding because it is out of scope.
Why it's wrong here
Deleting the finding withholds information the client needs about an unknown third party holding remote access to their network. Scope limits testing actions, not reporting of observations. The correct approach records it in a dedicated out-of-scope or informational section so the client can investigate and update the agreement.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.