PT0-002 Engagement Management Practice Question
The penetration tester identifies that a web application is hosted on a server that also contains sensitive customer data unrelated to the test. The SOW clearly states that only the web application is in scope. The tester accidentally accesses the customer data. What should the tester do immediately?
⚠ Common exam trap
PT0-003 often tests the misconception that a tester should handle an out-of-scope discovery quietly (delete, ignore, or investigate), when the exam expects immediate client notification and cessation of testing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the incident to the client and stop testing
When a penetration tester accesses data outside the scope defined in the SOW, the immediate action is to stop testing and report the incident to the client. This preserves the integrity of the engagement, allows the client to assess any regulatory or contractual implications, and prevents further unauthorized access. Continuing or deleting data would compound the scope violation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the data and continue as planned
Why it's wrong here
Deleting discovered data is a form of evidence spoliation and directly violates standard incident-handling principles. If the application is leaking sensitive data, the client may need to investigate the root cause, notify affected parties, or mount a legal defense, and the deleted material destroys the chain of custody. Furthermore, unilaterally altering or removing application data is outside the scope of a typical penetration test authorization, so the tester would be exceeding their mandate while also hiding a serious finding from the client.
- ✗
Continue testing and ignore the data
Why it's wrong here
Continuing the test as if nothing was seen is a willful failure to act on material information, and it also risks expanding the engagement deeper into unapproved territory. The tester has a contractual duty to report any suspected breach immediately under the rules of engagement, and ignoring the data means the client remains exposed to the underlying vulnerability without any chance to remediate. It also creates a false narrative that the tester never accessed the data, which is not credible if forensic logs later reveal the interaction.
- ✗
Analyze the data to find vulnerabilities
Why it's wrong here
While analyzing the data might seem like a way to determine the root cause, actually reading, copying, or querying sensitive out-of-scope data is an unauthorized processing act in itself, separate from the discovery that caught the tester's attention. Many jurisdictions' privacy laws and the test's own data-handling clauses mandate data minimization, meaning the tester should not examine content further than necessary to recognize it is out of scope. The appropriate move is to preserve the evidence and report it, not to perform a deeper investigation that could constitute a second, separate breach.
- ✓
Report the incident to the client and stop testing
Why this is correct
Stopping the test and reporting the incident is the only action that preserves both the evidence and the tester's professional integrity while aligning with incident-response procedures and the rules of engagement. The client has an incident response plan or would expect to be notified as a point of contact, so the tester should immediately escalate the discovery, halt all further testing, and let the client decide whether to involve law enforcement or take other protective action. This approach avoids unauthorized access to out-of-scope data and keeps the engagement within the agreed scope, which is the standard expected for a PT0-003 certified professional.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.