exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 36 discussion

Actual exam question from CompTIA's PT0-002
Question #: 36
Topic #: 1
[All PT0-002 Questions]

A penetration tester who is doing a security assessment discovers that a critical vulnerability is being actively exploited by cybercriminals.
Which of the following should the tester do NEXT?

  • A. Reach out to the primary point of contact.
  • B. Try to take down the attackers.
  • C. Call law enforcement officials immediately.
  • D. Collect the proper evidence and add to the final report.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
RRabbit_111
Highly Voted 1 year, 3 months ago
Selected Answer: A
A. Reach out to the primary point of contact The tester should immediately reach out to the primary point of contact (often known as the incident response team) to inform them of the ongoing attack. This will allow the organization to take immediate action to mitigate the attack and prevent further damage. The primary point of contact would be responsible for coordinating the incident response, including notifying other stakeholders, such as legal department, IT department, and management, about the incident. It's important to note that trying to take down the attackers, even if it's a valid option, should be done by experts and not by a penetration tester, and it's the incident response team responsibility, not the tester's. Calling law enforcement officials immediately would be a good idea, but the primary point of contact should be informed first. Finally, collecting the proper evidence and adding it to the final report is crucial, as it can be used to identify the attackers and assist in any legal action that may be taken against them. However, the main priority should be to stop the ongoing attack.
upvoted 9 times
...
solutionz
Most Recent 9 months ago
Selected Answer: A
In a situation where a critical vulnerability is being actively exploited, immediate communication with the client is paramount. The penetration tester's responsibility is to inform the client so they can take necessary action, not to engage with attackers or law enforcement directly. So, the correct next step would be: A. Reach out to the primary point of contact.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago