mediumMultiple Select
PT0-002 Practice Question: Which THREE of the following are best practices…
Which THREE of the following are best practices when communicating findings to stakeholders during a penetration test?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide regular status updates to the client point of contact
Option B is correct because providing regular status updates to the client point of contact keeps stakeholders informed of progress, emerging risks, and any scope or scheduling changes, which is a core engagement-management practice during a penetration test. Option D is correct because a critical vulnerability—such as an easily exploitable remote code execution or domain admin compromise—can cause immediate business impact, so the client must be notified right away through the agreed escalation path so they can begin containment and remediation. Option E is correct because effective stakeholder communication tailors technical depth to the audience: executives need business risk, impact, and remediation priorities, while technical staff need specifics like affected hosts, CVEs, and reproduction steps. Option A is not appropriate because sharing unsanitized raw exploit code and logs can leak sensitive data, credentials, or weaponized payloads beyond authorized recipients and violates data-handling and confidentiality obligations. Option C is not appropriate because including full technical details in every communication overwhelms non-technical stakeholders and ignores the need to adapt messaging to the audience and purpose of each report or briefing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Share raw exploit code and logs without sanitization
Why it's wrong here
Uns sanitised exploit code and logs can leak credentials, personal data and live attack techniques beyond the agreed scope, breaching confidentiality obligations. Tempting because raw evidence demonstrates impact convincingly, and would be correct when sharing with the technical remediation team under an agreed disclosure agreement.
- ✓
Provide regular status updates to the client point of contact
Why this is correct
Scheduled status updates to the nominated point of contact maintain a single trusted channel, keeping the client informed of progress and emerging risks throughout the engagement, which is the defined communication best practice for stakeholder engagement.
- ✗
Always include full technical details in every communication
Why it's wrong here
Dumping full technical detail into every communication overwhelms business stakeholders and can expose sensitive data to audiences lacking the context or clearance to interpret it. Tempting because completeness feels rigorous, and would be correct for the technical remediation report delivered to the engineering team.
- ✓
Notify the client immediately upon discovering a critical vulnerability
Why this is correct
Immediate notification satisfies the stem's critical-severity constraint by enabling remediation before the report is finalised. Critical findings, such as unauthenticated remote code execution or exposed Microsoft Entra ID credentials, demand out-of-band escalation rather than waiting for the closing debrief, limiting the window an attacker could exploit.
- ✓
Adjust the level of technical detail based on the audience
Why this is correct
Tailoring technical depth to each audience satisfies the stakeholder-communication constraint: executives need business risk and remediation priorities, while engineers require exploit detail and evidence. This ensures findings are understood and actioned rather than lost in irrelevant jargon, directly supporting the engagement's reporting objective.
Go deeper
Related to this question
Learn chapter
Source Code Review for Vulnerabilities
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.