Courseiva
mediumMultiple Select

PT0-002 Practice Question: Which THREE of the following are best practices…

Which THREE of the following are best practices when communicating findings to stakeholders during a penetration test?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Provide regular status updates to the client point of contact

Option B is correct because providing regular status updates to the client point of contact keeps stakeholders informed of progress, emerging risks, and any scope or scheduling changes, which is a core engagement-management practice during a penetration test. Option D is correct because a critical vulnerability—such as an easily exploitable remote code execution or domain admin compromise—can cause immediate business impact, so the client must be notified right away through the agreed escalation path so they can begin containment and remediation. Option E is correct because effective stakeholder communication tailors technical depth to the audience: executives need business risk, impact, and remediation priorities, while technical staff need specifics like affected hosts, CVEs, and reproduction steps. Option A is not appropriate because sharing unsanitized raw exploit code and logs can leak sensitive data, credentials, or weaponized payloads beyond authorized recipients and violates data-handling and confidentiality obligations. Option C is not appropriate because including full technical details in every communication overwhelms non-technical stakeholders and ignores the need to adapt messaging to the audience and purpose of each report or briefing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Share raw exploit code and logs without sanitization

    Why it's wrong here

    Uns sanitised exploit code and logs can leak credentials, personal data and live attack techniques beyond the agreed scope, breaching confidentiality obligations. Tempting because raw evidence demonstrates impact convincingly, and would be correct when sharing with the technical remediation team under an agreed disclosure agreement.

  • ✓

    Provide regular status updates to the client point of contact

    Why this is correct

    Scheduled status updates to the nominated point of contact maintain a single trusted channel, keeping the client informed of progress and emerging risks throughout the engagement, which is the defined communication best practice for stakeholder engagement.

  • ✗

    Always include full technical details in every communication

    Why it's wrong here

    Dumping full technical detail into every communication overwhelms business stakeholders and can expose sensitive data to audiences lacking the context or clearance to interpret it. Tempting because completeness feels rigorous, and would be correct for the technical remediation report delivered to the engineering team.

  • ✓

    Notify the client immediately upon discovering a critical vulnerability

    Why this is correct

    Immediate notification satisfies the stem's critical-severity constraint by enabling remediation before the report is finalised. Critical findings, such as unauthenticated remote code execution or exposed Microsoft Entra ID credentials, demand out-of-band escalation rather than waiting for the closing debrief, limiting the window an attacker could exploit.

  • ✓

    Adjust the level of technical detail based on the audience

    Why this is correct

    Tailoring technical depth to each audience satisfies the stakeholder-communication constraint: executives need business risk and remediation priorities, while engineers require exploit detail and evidence. This ensures findings are understood and actioned rather than lost in irrelevant jargon, directly supporting the engagement's reporting objective.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.