easyMultiple Choice
PT0-002 Practice Question: Is the most appropriate evidence to include in a…
Which of the following is the most appropriate evidence to include in a penetration testing report for a SQL injection vulnerability?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Screenshots of the successful injection with timestamps
Screenshots with timestamps provide clear visual evidence of the exploitation and help validate the finding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A verbal description of the exploit
Why it's wrong here
A verbal description cannot be independently verified or reproduced by the client's technical team; it lacks the concrete payload, request/response details, and visual confirmation needed to prove the injection actually succeeded. Without a timestamped artifact, the finding remains anecdotal and cannot distinguish a confirmed vulnerability from a theoretical risk, making it unsuitable as formal evidence in a penetration test report.
- ✓
Screenshots of the successful injection with timestamps
Why this is correct
Timestamped screenshots constitute definitive proof of exploitability because they capture the exact injection payload, the targeted parameter, and the resulting application response or database error, demonstrating the impact in real time. The timestamp establishes a verifiable audit trail, and the visual record allows the client to confirm the finding, prioritize remediation, and satisfy evidence requirements for regulatory compliance or insurance claims.
- ✗
A link to a public exploit database
Why it's wrong here
A link to a public exploit database only references a potentially applicable exploit or vulnerability, but it does not confirm that the client's specific application version, configuration, or environment is affected. Moreover, the linked exploit may have been patched, may require different conditions, or may be a PoC that fails to work in this context, so it cannot substitute for environment-specific validation and evidence of success.
- ✗
Raw source code of the application
Why it's wrong here
Raw source code is not evidence of successful exploitation; it merely reveals application logic that could theoretically contain vulnerabilities, but it does not demonstrate that an attacker can reach that code or that the injection would execute. Additionally, including source code in a report may expose proprietary or sensitive information, and the sheer volume of irrelevant code could obscure the actual finding rather than confirm it.
Go deeper
Related to this question
Learn chapter
Re-Testing and Validation Testing
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.