PT0-002 Engagement Management Practice Question
Which penetration testing standard provides a step-by-step methodology from pre-engagement through post-engagement activities, including intelligence gathering, vulnerability analysis, and exploitation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PTES
PTES (Penetration Testing Execution Standard) covers the entire lifecycle of a penetration test.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PTES
Why this is correct
The Penetration Testing Execution Standard (PTES) is explicitly designed as a step-by-step methodology for conducting penetration tests. It defines seven distinct phases—pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting—each with detailed technical guidance and deliverables. This lifecycle coverage makes PTES the most complete answer for a standard that walks an assessor through the entire engagement from scoping to final report.
- ✗
OSSTMM
Why it's wrong here
The Open Source Security Testing Methodology Manual (OSSTMM) is a peer-reviewed framework for auditing and measuring operational security controls, focusing on trust boundaries and quantifiable metrics like the Attack Surface and Protection Vector. While it provides a structured approach to security testing, it does not offer a prescriptive, step-by-step penetration test execution process with phases such as exploitation and post-exploitation. Its emphasis is on verification and metrics, not the attacker-centric, iterative methodology that PTES provides.
- ✗
OWASP Testing Guide
Why it's wrong here
The OWASP Testing Guide is a specialized resource focused exclusively on web application security testing, providing detailed checklists and techniques for web vulnerabilities like injection, broken authentication, and XSS. Its scope is intentionally narrow—web applications—and it does not cover the broader penetration testing lifecycle, which includes network discovery, physical security, social engineering, or post-exploitation activities. Thus, while useful for the web application portion of a pentest, it is not a comprehensive step-by-step standard for overall penetration testing.
- ✗
NIST SP 800-115
Why it's wrong here
NIST SP 800-115 is a technical guide for information security testing and assessment that discusses planning, executing, and reporting security tests, but it is written as a general assessment guideline for federal agencies rather than a step-by-step penetration testing methodology. It offers high-level guidance and common techniques (e.g., network scanning, password cracking) but lacks the detailed, sequential phases and engagement-specific deliverables that PTES defines. Furthermore, NIST SP 800-115 is not a standard in the same formal sense as PTES, which was created by a consortium of penetration testing experts specifically to standardize the methodology.
Go deeper
Related to this question
Learn chapter
Scope, Rules of Engagement, and Legal
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.