Courseiva
mediumMultiple Choice

PT0-002 Practice Question: Contracted to perform a penetration test for a…

You are contracted to perform a penetration test for a healthcare organization. During the testing, you discover a critical SQL injection vulnerability that exposes patient health information. The deadline for the final report is one week away. The client's IT manager asks you to exclude this finding from the report because they are already aware of it and are working on a fix. The IT manager claims that including it would cause panic among stakeholders. What is the BEST course of action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Explain that findings must be included in the report regardless of awareness, and offer to present the finding in a controlled manner to management

Option B is correct because a penetration tester has an ethical and professional obligation to report all discovered vulnerabilities, especially a critical SQL injection exposing patient health information, which may also trigger HIPAA breach-notification duties; the tester should refuse to omit it while offering a controlled, confidential briefing to management to reduce panic. This preserves report integrity and the client's ability to remediate and meet regulatory obligations. Option A is wrong because agreeing to exclude the finding, even with a verbal note, still suppresses a material risk from the official record. Option C is wrong because bypassing the IT manager to notify the compliance officer unilaterally breaks the agreed communication channel and may not be the proper escalation path. Option D is wrong because relegating a critical finding to a technical appendix still hides it from the executive summary and key decision-makers who need to act on it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Agree to exclude it but note it verbally

    Why it's wrong here

    Agreeing to omit a finding from the written report—even with a verbal caveat—compromises the integrity and auditability of the assessment. Verbal notes are not part of the official report and risk being ignored or forgotten, and the lack of a documented trail could leave the client exposed to the very risk you identified. It also sets a dangerous precedent that findings can be suppressed by request, which violates the impartiality expected of a penetration tester.

  • ✓

    Explain that findings must be included in the report regardless of awareness, and offer to present the finding in a controlled manner to management

    Why this is correct

    A penetration test report is an objective record of observed vulnerabilities, and filtering out a known issue misrepresents the client's security posture and may misdirect remediation resources. You should explain that all findings must remain in the report regardless of the client's awareness, while offering to present the finding in a controlled manner—such as framing it with mitigation context for management. This maintains integrity while addressing the IT manager's concern about stakeholder reaction, and it upholds the professional standards outlined in the PT0-003 scope.

  • ✗

    Report the issue to the client's compliance officer without informing the IT manager

    Why it's wrong here

    Reporting directly to the compliance officer while deliberately bypassing the IT manager violates the agreed communication plan and undermines the working relationship with your primary technical contact. It can create internal conflict and trigger defensive reactions, potentially delaying remediation of the exact issue you are trying to surface. Unless the rules of engagement specifically authorize that escalation path, this is a process failure, not a security solution, and it could damage trust across the client organization.

  • ✗

    Include it only in the technical appendix

    Why it's wrong here

    Relegating the finding to a technical appendix satisfies the letter of 'inclusion' but violates the spirit of effective reporting by masking its risk severity and hiding it from decision-makers. Appendices are intended for raw data, IOCs, or attack path artifacts, not for critical findings that require management attention. The finding should instead appear in the executive summary and remediation sections so leadership understands the business impact and allocates resources accordingly, ensuring the report drives appropriate action.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.