Courseiva
easyMultiple Choice

PT0-002 Practice Question: When a client disagrees with a finding's severity…

When a client disagrees with a finding's severity rating, what is the best approach for the penetration tester?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Discuss the rationale and adjust if valid business context is provided

The tester should listen to the client's perspective and discuss the risk assessment, providing rationale to explain the rating.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Discuss the rationale and adjust if valid business context is provided

    Why this is correct

    Severity in a penetration test is computed from evidence (CVSS metrics, exploitability, and impact) but is not absolute; business context—such as compensating controls, asset criticality, or exposure—can legitimately alter that score. A tester should walk through the CVSS vector and risk equation with the client, and if the client supplies valid environmental factors that justify a change, recalibrate the rating. This keeps the report both evidence-based and tailored to the client's actual risk posture.

  • ✗

    Escalate to the tester's manager

    Why it's wrong here

    Escalating to the tester's manager bypasses the collaborative dispute-resolution step that ethical penetration testing requires and treats a technical disagreement as a chain-of-command issue. Severity debates are about evidence and risk interpretation, not authority, so the tester should first reconcile the finding with the client by comparing technical data (e.g., CVSS environmental metrics) and clarifying what the client believes is inaccurate. If the client refuses a reasonable resolution, then documented escalation may be appropriate, but it is not the first move.

  • ✗

    Insist on the original rating and refuse to change it

    Why it's wrong here

    Severity ratings are inherently contextual; a vulnerability that is critical in one environment may be low in another because of compensating controls, network segmentation, or the value of the data at risk. Refusing to revisit the original rating ignores these environmental and business factors and treats the initial CVSS base score as immutable. This rigidity can damage client trust and produce a report that does not reflect the client's actual exposure, undermining the goal of an accurate risk assessment.

  • ✗

    Lower the rating to satisfy the client

    Why it's wrong here

    Lowering a severity rating to appease the client is an integrity violation because it decouples the finding's risk level from the objective evidence gathered during testing. The tester's obligation is to provide an honest risk picture; altering a score without a corresponding technical or environmental justification can leave a critical vulnerability unaddressed and exposes the client to a breach that a compliant report would have highlighted. Such behavior also breaches the testing agreement's ethical standards and consent requirements.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.