exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 209 discussion

Actual exam question from CompTIA's PT0-002
Question #: 209
Topic #: 1
[All PT0-002 Questions]

A penetration tester joins the assessment team in the middle of the assessment. The client has asked the team, both verbally and in the scoping document, not to test the production networks. However, the new tester is not aware of this request and proceeds to perform exploits in the production environment. Which of the following would have MOST effectively prevented this misunderstanding?

  • A. Prohibiting exploitation in the production environment
  • B. Requiring all testers to review the scoping document carefully
  • C. Never assessing the production networks
  • D. Prohibiting testers from joining the team during the assessment
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Willz01
5 months ago
Selected Answer: D
D would have MOST effectivley prevented this. Theyre not asking for anything other than what is the most effective way to prevent the tester that joined mid engagement. This completely prevents it, B does not. This just comes down to understanding the question asked.
upvoted 1 times
kinny4000
2 months, 3 weeks ago
If the question explicitly asked for the absolute best way to prevent this issue, regardless of practicality, then D would be valid. But in professional penetration testing, B is the best answer because it's effective AND realistic.
upvoted 1 times
...
...
Paula77
9 months, 3 weeks ago
Selected Answer: B
It's part of a Pen Tester job to follow the rules laid out in the SOW.
upvoted 1 times
...
pepgua
10 months, 3 weeks ago
The MOST effective prevention for this misunderstanding is: B. Requiring all testers to review the scoping document carefully D. Prohibiting testers from joining the team during the assessment: This is too restrictive and hinders flexibility. New team members can be valuable, but proper onboarding and communication are crucial. Requiring a thorough review of the scoping document ensures all testers, including those joining mid-assessment, are aware of the boundaries and limitations of the testing. This document should explicitly state the exclusion of the production environment.
upvoted 2 times
...
Meep123
1 year, 3 months ago
Selected Answer: D
"BEST" = most effective. BEST at preventing this exact situation would be to DENY ALL, rather than "Read and follow rules". 0% vs 1%, 0% wins.
upvoted 3 times
j904
1 year ago
I agree
upvoted 1 times
...
...
solutionz
1 year, 8 months ago
Selected Answer: B
In this scenario, the issue is a lack of communication and understanding of the constraints and boundaries set by the client. The most effective way to prevent this misunderstanding would have been to ensure that all members of the assessment team, including those joining mid-assessment, are fully aware of the requirements and restrictions defined in the scoping document. Option B, "Requiring all testers to review the scoping document carefully," directly addresses this issue by making sure that everyone involved in the assessment is aware of the client's requests and the scope of the assessment. Therefore, option B would have been the most effective way to prevent this misunderstanding.
upvoted 4 times
...
matheusfmartins
1 year, 8 months ago
Selected Answer: B
It's B, the testers should read the documentations before getting into an engagement.
upvoted 2 times
...
scweeb
1 year, 8 months ago
To me answer is B. Lets say you have testers who get sick and can no longer perform but the company has others on hand who can step in to continue the test and meet company SOW. You would allow that new tester with the understanding that they are briefed like all the current testers and they read the required documents.
upvoted 2 times
...
AaronS1990
2 years ago
Selected Answer: D
"The client has asked the team, both verbally and in the scoping document, not to test the production networks. However, the new tester is not aware of this request"This means that it was already written in the scoping document and the pentester missed it anyway. So just saying "read it more caefully next time still leaves the chance it will be missed in future. If you go with D you remove the risk of this entirely. Additionally the client asked verbally. Had someone not have joined halfway through the pentest then they would likely have been there to hear this request in person, so despite missing it in the scoping document they still would've been aware of the restriction. Another thing that steers me towards D
upvoted 2 times
...
AaronS1990
2 years ago
Surely D is the BEST? Just because they read it carefully doesn't mean it won't happen again due to user error. If you don't let people join mid-way through that removes the risk entirely rather than mitigating it
upvoted 2 times
Paula77
9 months, 3 weeks ago
That's the reason a SOW is signed so everybody knows what to do and what the rules are. It is part of the job to follow the rules. What if you have a member of the existing team that gets sick, another one resigns and another one dies. You will continue the assessment -3 people and hope for the best because you believe that joining mid-assessment is out of question. Funny! :)
upvoted 1 times
...
Meep123
1 year, 3 months ago
Agree.
upvoted 1 times
...
...
lifehacker0777
2 years, 1 month ago
Selected Answer: B
__BBB__
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago