PT0-002 Engagement Management Practice Question
Which of the following penetration testing standards includes detailed guidelines for pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PTES
PTES (Penetration Testing Execution Standard) covers the entire testing lifecycle from pre-engagement to reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OSSTMM
Why it's wrong here
OSSTMM is a methodology for security testing that emphasizes operational security metrics and controls, rather than a step-by-step penetration testing process. It lacks comprehensive guidance on pre-engagement activities, scoping, and reporting that are essential to a full pentest. While it can be used for assessing specific operational security aspects, it does not cover all phases of a penetration test from reconnaissance to post-exploitation.
- ✗
OWASP Testing Guide
Why it's wrong here
The OWASP Testing Guide is specifically designed for web application security testing, providing a comprehensive checklist for application-level vulnerabilities. It does not address the full scope of a penetration test, such as network infrastructure, wireless, social engineering, or physical security. Moreover, it lacks the formalized pre-engagement and reporting phases that a standard like PTES includes, limiting its applicability as an overarching pentest standard.
- ✗
NIST SP 800-115
Why it's wrong here
NIST SP 800-115 is a technical guide for information security testing and assessment, but it is not a penetration testing standard that defines a complete methodology. It focuses on the technical aspects of conducting assessments, including techniques and tools, but provides limited guidance on pre-engagement, scoping, and risk management. This makes it less comprehensive for a full penetration test engagement compared to PTES.
- ✓
PTES
Why this is correct
PTES (Penetration Testing Execution Standard) is the only option that expressly defines a complete penetration testing methodology from start to finish. It covers pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This makes it a comprehensive standard suitable for guiding all phases of a professional penetration test.
Go deeper
Related to this question
Learn chapter
Phishing Campaigns in Penetration Testing
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Post-exploitation
Post-exploitation is the phase of a penetration test that begins after an attacker has gained initial access to a system, focusing on maintaining access, escalating privileges, moving laterally, and achieving the test's objectives.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.