PT0002 CompTIA PenTest+ Certification Exam Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

During a comprehensive network penetration test for a financial services firm, a tester identifies a misconfigured cloud storage bucket containing personally identifiable information (PII) of the firm\'s customers, which falls outside the initially defined scope of the engagement. The firm\'s Chief Information Security Officer (CISO) had explicitly stated during the kickoff meeting that any findings, regardless of scope, should be reported immediately through a secure, encrypted channel.

Which of the following actions best adheres to professional ethical standards and the agreed-upon Rules of Engagement?

Securely document the misconfiguration and the sensitive data, then immediately report the finding to the client's designated point of contact via the agreed-upon encrypted communication channel, recommending a prompt remediation.
Ignore the finding as it falls outside the agreed-upon scope to avoid scope creep and potential client dissatisfaction with unexpected additional work.
Immediately attempt to remediate the misconfiguration independently to protect the client's data, documenting the actions taken for later reporting.
Share the details of the misconfiguration and the sensitive data with a trusted colleague within the testing firm to seek advice on how to proceed without directly involving the client yet.

About the PT0002 CompTIA PenTest+ Certification Exam Certification

These free practice questions are designed to help you assess your readiness for the PT0002 CompTIA PenTest+ Certification Exam exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.