nerdexam
CompTIA

PT0-003 · Question #293

A company's incident response team determines that a breach occurred because a penetration tester left a web shell. Which of the following should the penetration tester have done after the engagement?

Sign in or unlock PT0-003 to reveal the answer and full explanation for question #293. The question stem and answer options stay visible for context.

Submitted by chen.hong· Mar 6, 2026Engagement management

Question

A company's incident response team determines that a breach occurred because a penetration tester left a web shell. Which of the following should the penetration tester have done after the engagement?

Options

  • AEnable a host-based firewall on the machine
  • BRemove utilized persistence mechanisms on client systems
  • CRevert configuration changes made during the engagement
  • DTurn off command-and-control infrastructure

Unlock PT0-003 to see the answer

You've previewed enough free PT0-003 questions. Unlock PT0-003 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#post-engagement cleanup#persistence mechanisms#web shells#ethical hacking
Full PT0-003 Practice