Courseiva
Engagement Management →easyMultiple Choice

PT0-002 Engagement Management Practice Question

Which penetration testing standard provides a step-by-step methodology from pre-engagement through post-engagement activities, including intelligence gathering, vulnerability analysis, and exploitation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PTES

PTES (Penetration Testing Execution Standard) covers the entire lifecycle of a penetration test.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PTES

    Why this is correct

    The Penetration Testing Execution Standard (PTES) is explicitly designed as a step-by-step methodology for conducting penetration tests. It defines seven distinct phases—pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting—each with detailed technical guidance and deliverables. This lifecycle coverage makes PTES the most complete answer for a standard that walks an assessor through the entire engagement from scoping to final report.

  • ✗

    OSSTMM

    Why it's wrong here

    The Open Source Security Testing Methodology Manual (OSSTMM) is a peer-reviewed framework for auditing and measuring operational security controls, focusing on trust boundaries and quantifiable metrics like the Attack Surface and Protection Vector. While it provides a structured approach to security testing, it does not offer a prescriptive, step-by-step penetration test execution process with phases such as exploitation and post-exploitation. Its emphasis is on verification and metrics, not the attacker-centric, iterative methodology that PTES provides.

  • ✗

    OWASP Testing Guide

    Why it's wrong here

    The OWASP Testing Guide is a specialized resource focused exclusively on web application security testing, providing detailed checklists and techniques for web vulnerabilities like injection, broken authentication, and XSS. Its scope is intentionally narrow—web applications—and it does not cover the broader penetration testing lifecycle, which includes network discovery, physical security, social engineering, or post-exploitation activities. Thus, while useful for the web application portion of a pentest, it is not a comprehensive step-by-step standard for overall penetration testing.

  • ✗

    NIST SP 800-115

    Why it's wrong here

    NIST SP 800-115 is a technical guide for information security testing and assessment that discusses planning, executing, and reporting security tests, but it is written as a general assessment guideline for federal agencies rather than a step-by-step penetration testing methodology. It offers high-level guidance and common techniques (e.g., network scanning, password cracking) but lacks the detailed, sequential phases and engagement-specific deliverables that PTES defines. Furthermore, NIST SP 800-115 is not a standard in the same formal sense as PTES, which was created by a consortium of penetration testing experts specifically to standardize the methodology.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.