Courseiva
Engagement Management →mediumMultiple Choice

PT0-002 Engagement Management Practice Question

Which of the following penetration testing standards includes detailed guidelines for pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PTES

PTES (Penetration Testing Execution Standard) covers the entire testing lifecycle from pre-engagement to reporting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    OSSTMM

    Why it's wrong here

    OSSTMM is a methodology for security testing that emphasizes operational security metrics and controls, rather than a step-by-step penetration testing process. It lacks comprehensive guidance on pre-engagement activities, scoping, and reporting that are essential to a full pentest. While it can be used for assessing specific operational security aspects, it does not cover all phases of a penetration test from reconnaissance to post-exploitation.

  • ✗

    OWASP Testing Guide

    Why it's wrong here

    The OWASP Testing Guide is specifically designed for web application security testing, providing a comprehensive checklist for application-level vulnerabilities. It does not address the full scope of a penetration test, such as network infrastructure, wireless, social engineering, or physical security. Moreover, it lacks the formalized pre-engagement and reporting phases that a standard like PTES includes, limiting its applicability as an overarching pentest standard.

  • ✗

    NIST SP 800-115

    Why it's wrong here

    NIST SP 800-115 is a technical guide for information security testing and assessment, but it is not a penetration testing standard that defines a complete methodology. It focuses on the technical aspects of conducting assessments, including techniques and tools, but provides limited guidance on pre-engagement, scoping, and risk management. This makes it less comprehensive for a full penetration test engagement compared to PTES.

  • ✓

    PTES

    Why this is correct

    PTES (Penetration Testing Execution Standard) is the only option that expressly defines a complete penetration testing methodology from start to finish. It covers pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This makes it a comprehensive standard suitable for guiding all phases of a professional penetration test.

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.