exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 97 discussion

Actual exam question from CompTIA's PT0-002
Question #: 97
Topic #: 1
[All PT0-002 Questions]

Which of the following situations would require a penetration tester to notify the emergency contact for the engagement?

  • A. The team exploits a critical server within the organization.
  • B. The team exfiltrates PII or credit card data from the organization.
  • C. The team loses access to the network remotely.
  • D. The team discovers another actor on a system on the network.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
fuzzyguzzy
11 months, 2 weeks ago
Selected Answer: D
The correct answer is D.
upvoted 1 times
...
TacosInMyBelly
1 year, 7 months ago
Selected Answer: D
All of the other ones wouldn't warrant an emergency contact. If they found another actor on the network that shouldn't be there while they're playing the enemy then that is means for halting the penetration test all together and notifying them. They will the need to have their security department look further into it to see if there network is being exploited as that is the worst case scenario for an organization.
upvoted 2 times
...
Alizade
1 year, 9 months ago
Selected Answer: B
The correct answer is B. The team exfiltrates PII or credit card data from the organization.
upvoted 1 times
...
[Removed]
1 year, 9 months ago
Emergency contact is not for reporting critical vulnerabilities. You report those to the IT manager or the primary contact. Emergency contact is in case you cause something on the network which requires deconfliction. They are there for network and resource availability, so if you lose connection to the network, that's a job for the emergency personnel. If there is another actor on the network, that won't be reported to the emergency contact. That will go the primary contact or the designated IT manager or client counterpart.
upvoted 3 times
...
UseChatGPT
1 year, 10 months ago
Selected Answer: B
B. Listen to ChatGPT on this one.
upvoted 1 times
hakanay
1 year, 8 months ago
Don't ask 3.5, ask 4. It's clearly D.
upvoted 1 times
...
581777a
1 year, 10 months ago
It said : Option C: Losing remote access to the network during a penetration test is a critical situation that could indicate an issue with the engagement, potential compromise, or other unforeseen problems. In such cases, it is important to notify the emergency contact or the organization's incident response team promptly. This allows the organization to assess the situation, ensure that the engagement did not lead to unintended consequences, and take necessary actions to restore network access and security. I mentioned D and it basically said "ok fine. both but it depends on the specific circumstances"
upvoted 2 times
...
...
solutionz
2 years ago
Selected Answer: D
During a penetration testing engagement, the penetration testers usually have rules of engagement and boundaries that they must follow. Notifying the emergency contact would be warranted if something unexpected and potentially harmful was encountered. In the given options, the situation that most likely would require immediate notification of the emergency contact is: D. The team discovers another actor on a system on the network. Discovering another unauthorized actor on the system could mean that there's an ongoing breach or other malicious activity. This situation would generally be considered an emergency, as it goes beyond the planned scope of the penetration test and represents an immediate risk to the organization. The other options might be part of the planned scope of the test or not represent immediate emergencies, depending on the particular circumstances of the engagement.
upvoted 1 times
...
JimBobSquare101
2 years, 2 months ago
I would roll with B....CC data loss will be a whole legal headache...
upvoted 1 times
...
xviruz2kx
2 years, 4 months ago
Selected Answer: B
All of the listed situations could potentially warrant notifying the emergency contact for the engagement, but the most critical and urgent situation that requires immediate notification is option B - exfiltrating PII or credit card data from the organization. This type of data is highly sensitive and its unauthorized disclosure can lead to significant financial and reputational damage for the organization.
upvoted 1 times
MegTechGuru
1 year, 9 months ago
No, because if you exfiltrated pii or credit card data, this is likely already to be expected and it should be listed for something you will remediate as well as they can be informed. Its a much bigger deal if there is an actor on the network who could exploit that information and your emergency contact should be notified. as a penetration tester you would almost hope you could find pii or credit card data as this would be a success for you
upvoted 2 times
...
...
[Removed]
2 years, 5 months ago
D is the correct answer
upvoted 2 times
...
cy_analyst
2 years, 5 months ago
Selected Answer: D
A or D both are so important for the others I think I can write a report.
upvoted 3 times
...
josepa
2 years, 5 months ago
b y d?
upvoted 2 times
[Removed]
2 years, 5 months ago
D is the answer
upvoted 2 times
...
...
kloug
2 years, 5 months ago
bbbbbbbbbbbbbb
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...