exam questions

Exam PT1-002 All Questions

View all questions & answers for the PT1-002 exam

Exam PT1-002 topic 1 question 23 discussion

Actual exam question from CompTIA's PT1-002
Question #: 23
Topic #: 1
[All PT1-002 Questions]

A penetration tester who is doing a security assessment discovers that a critical vulnerability is being actively exploited by cybercriminals. Which of the following should the tester do NEXT?

  • A. Reach out to the primary point of contact
  • B. Try to take down the attackers
  • C. Call law enforcement officials immediately
  • D. Collect the proper evidence and add to the final report
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BinarySoldier
Highly Voted 3 years, 5 months ago
A is correct. When an active exploitation is noticed during the engagement, everything thing else MUST be put on hold and contact the client immediately.
upvoted 6 times
...
bieecop
Most Recent 1 year, 9 months ago
Selected Answer: A
In this scenario, the penetration tester should inform the primary point of contact within the organization or the client who requested the security assessment. The primary point of contact could be the client's security team, the project manager, or a designated individual responsible for overseeing the assessment. By immediately notifying the primary point of contact, the tester enables the client to take appropriate actions to mitigate the vulnerability and respond to the active exploitation.
upvoted 1 times
...
ronniehaang
2 years, 3 months ago
Selected Answer: A
Communication triggers - Critical findings
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago