PT0-001 · Question #7
Which of the following situations would cause a penetration tester to communicate with a system owner/ client during the course of a test? (Select TWO.)
The correct answer is B. The system shows evidence of prior unauthorized compromise. D. The system becomes unavailable following an attempted exploit. During a penetration test, testers must immediately notify the client when an unintended service disruption occurs or when evidence of a prior unauthorized breach is discovered, as both situations carry significant operational and legal implications.
Question
Which of the following situations would cause a penetration tester to communicate with a system owner/ client during the course of a test? (Select TWO.)
Options
- AThe tester discovers personally identifiable data on the system.
- BThe system shows evidence of prior unauthorized compromise.
- CThe system shows a lack of hardening throughout.
- DThe system becomes unavailable following an attempted exploit.
- EThe tester discovers a finding on an out-of-scope system.
How the community answered
(63 responses)- A5% (3)
- B71% (45)
- C8% (5)
- E16% (10)
Why each option
During a penetration test, testers must immediately notify the client when an unintended service disruption occurs or when evidence of a prior unauthorized breach is discovered, as both situations carry significant operational and legal implications.
Discovering PII on a system is a notable finding to document in the final report but does not typically require immediate out-of-band escalation during the test, as encountering sensitive data is an expected and authorized outcome of the assessment.
Evidence of a prior unauthorized compromise indicates an active or historical breach by a third party outside the engagement scope, which is a critical incident requiring immediate client notification so proper incident response procedures can be initiated.
A lack of system hardening is a standard vulnerability finding that belongs in the final penetration test report rather than being escalated as an emergency requiring immediate client contact.
If a system becomes unavailable as a result of an attempted exploit, the tester must immediately notify the client because this is an unintended outage that could impact business operations and may require rapid recovery actions outside the tester's authority.
A finding on an out-of-scope system should be noted, excluded from active exploitation, and disclosed in the final report or a brief notification - it does not represent the same urgency as an active service outage or evidence of an external breach.
Concept tested: Penetration test communication triggers and escalation procedures
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.