easyMultiple Choice
PT0-002 Practice Question: When a client disagrees with a finding's severity…
When a client disagrees with a finding's severity rating, what is the best approach for the penetration tester?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Discuss the rationale and adjust if valid business context is provided
The tester should listen to the client's perspective and discuss the risk assessment, providing rationale to explain the rating.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Discuss the rationale and adjust if valid business context is provided
Why this is correct
Severity in a penetration test is computed from evidence (CVSS metrics, exploitability, and impact) but is not absolute; business context—such as compensating controls, asset criticality, or exposure—can legitimately alter that score. A tester should walk through the CVSS vector and risk equation with the client, and if the client supplies valid environmental factors that justify a change, recalibrate the rating. This keeps the report both evidence-based and tailored to the client's actual risk posture.
- ✗
Escalate to the tester's manager
Why it's wrong here
Escalating to the tester's manager bypasses the collaborative dispute-resolution step that ethical penetration testing requires and treats a technical disagreement as a chain-of-command issue. Severity debates are about evidence and risk interpretation, not authority, so the tester should first reconcile the finding with the client by comparing technical data (e.g., CVSS environmental metrics) and clarifying what the client believes is inaccurate. If the client refuses a reasonable resolution, then documented escalation may be appropriate, but it is not the first move.
- ✗
Insist on the original rating and refuse to change it
Why it's wrong here
Severity ratings are inherently contextual; a vulnerability that is critical in one environment may be low in another because of compensating controls, network segmentation, or the value of the data at risk. Refusing to revisit the original rating ignores these environmental and business factors and treats the initial CVSS base score as immutable. This rigidity can damage client trust and produce a report that does not reflect the client's actual exposure, undermining the goal of an accurate risk assessment.
- ✗
Lower the rating to satisfy the client
Why it's wrong here
Lowering a severity rating to appease the client is an integrity violation because it decouples the finding's risk level from the objective evidence gathered during testing. The tester's obligation is to provide an honest risk picture; altering a score without a corresponding technical or environmental justification can leave a critical vulnerability unaddressed and exposes the client to a breach that a compliant report would have highlighted. Such behavior also breaches the testing agreement's ethical standards and consent requirements.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.