PT0-002 Engagement Management Practice Question
During post-engagement, a penetration tester needs to ensure proper data handling. Which THREE actions should the tester take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Securely destroy test artifacts after the client accepts the report
After the engagement, test artifacts should be securely destroyed, data should be purged from test systems, and confidential information must be handled per agreement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Securely destroy test artifacts after the client accepts the report
Why this is correct
Securely destroying test artifacts after client acceptance is the final step in the data lifecycle, requiring methods such as cryptographic erase or physical shredding to render data unrecoverable. This includes scan reports, payloads, captured credentials, and network captures stored on assessment laptops or servers. Retention beyond acceptance is unnecessary unless the contract explicitly permits it, making immediate destruction a standard practice to minimize exposure.
- ✓
Purge any data stored on test systems used during the engagement
Why this is correct
Purging test systems involves removing all client data and test-generated data from VMs, cloud instances, or physical hardware used during the assessment. Simple file deletion is insufficient; you must also clear temporary files, swap partitions, memory dumps, and any snapshots to ensure no recoverable remnants remain. This prevents accidental leakage of client data into other engagements or production environments, reducing cross-contamination and security risk.
- ✗
Retain all test data indefinitely for future reference
Why it's wrong here
Retaining all test data indefinitely violates data minimization principles and creates an unnecessary security liability if the data is ever breached. Most penetration testing contracts specify retention terms, and indefinite storage is typically not compliant with privacy regulations like GDPR or HIPAA. Furthermore, holding sensitive client data beyond the agreed period breaches trust and could expose the tester to legal action if a leak occurs.
- ✓
Follow the agreed-upon data handling procedures in the contract
Why this is correct
Following contractual data handling procedures is a legal and ethical mandate that covers how data is collected, accessed, encrypted, and stored during the engagement. These procedures often align with the client's security policies and regulatory requirements, specifying allowed tools, data classification, and access restrictions. Adherence ensures that all actions are defensible and that the tester avoids unauthorized handling that could void liability coverage or breach compliance standards.
- ✗
Share findings with other clients to demonstrate expertise
Why it's wrong here
Sharing findings with other clients is a clear violation of confidentiality agreements and NDAs because pentest reports contain sensitive details about vulnerabilities, network architecture, and business context. Even if anonymized, such data can be inferred or used to target the original client, and unauthorized disclosure may breach GDPR or HIPAA if personal data is involved. Ethical practice requires obtaining explicit, written consent before using client data for any purpose beyond the engagement.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.