nerdexam
CompTIA

PT0-003 · Question #299

Hotspot Question A penetration tester has identified a series of files throughout an assessment. INSTRUCTIONS Select the most appropriate action the penetration tester should take for each file. The…

The correct answer is Benefits (Accessible To: All Internet Users): Select Action; Employee Performance (Accessible To: All Corporate Employees): Select Action; Prospective Acquisitions (Accessible To: All Corporate Employees): Select Action; Draft- Press Release - Final (Accessible To: All Internet Users): Select Action. This hotspot question tests a penetration tester's ability to correctly categorize and act upon files discovered during an assessment, choosing the most appropriate action (e.g., exfiltrate, document, delete, leave in place, or escalate) for each file type found.

Submitted by haruto_sh· Mar 6, 2026Engagement management

Question

Hotspot Question A penetration tester has identified a series of files throughout an assessment. INSTRUCTIONS Select the most appropriate action the penetration tester should take for each file. The same action may be selected multiple times. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button. Answer:

Exhibits

PT0-003 question #299 exhibit 1
PT0-003 question #299 exhibit 2

Answer Area

  • Benefits (Accessible To: All Internet Users)Select Action
    Select ActionNotate in reportRecommend to change file permissionsRecommend to delete fileRecommend to contact mediaRecommend to report to regulatory authorities
  • Employee Performance (Accessible To: All Corporate Employees)Select Action
    Select ActionNotate in reportRecommend to change file permissionsRecommend to delete fileRecommend to contact mediaRecommend to report to regulatory authorities
  • Prospective Acquisitions (Accessible To: All Corporate Employees)Select Action
    Select ActionNotate in reportRecommend to change file permissionsRecommend to delete fileRecommend to contact mediaRecommend to report to regulatory authorities
  • Draft- Press Release - Final (Accessible To: All Internet Users)Select Action
    Select ActionNotate in reportRecommend to change file permissionsRecommend to delete fileRecommend to contact mediaRecommend to report to regulatory authorities

Explanation

This hotspot question tests a penetration tester's ability to correctly categorize and act upon files discovered during an assessment, choosing the most appropriate action (e.g., exfiltrate, document, delete, leave in place, or escalate) for each file type found.

Approach. A penetration tester must evaluate each discovered file based on its sensitivity, relevance to the engagement scope, and rules of engagement. Sensitive files containing credentials, PII, or proprietary data should be documented and reported (not exfiltrated unless explicitly authorized), while system files or logs relevant to vulnerabilities should be noted as evidence. Files that could indicate active threat actor presence should be escalated immediately. The penetration tester should never delete, alter, or exfiltrate data beyond what is explicitly permitted in the Statement of Work (SOW) or Rules of Engagement (ROE), and all findings must be documented with integrity to maintain a clear audit trail.

Concept tested. Penetration testing ethics, rules of engagement, and proper handling of discovered files during an assessment - including evidence collection, documentation, escalation procedures, and legal/contractual boundaries defined in the SOW and ROE.

Reference. CompTIA PenTest+ Exam Objectives: Domain 1 - Planning and Scoping (Rules of Engagement, handling sensitive data); Domain 5 - Reporting and Communication (documentation of findings and evidence handling)

Topics

#reporting#data classification#remediation recommendations#file permissions

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice