Skip to content

Engagement Management Questions

Practice questions for Engagement Management topic in CompTIA PenTest+. 14 questions covering this domain.

14 questions4 easy6 medium4 hard
Q1
medium

During a penetration test, the tester discovers evidence of an active data breach unrelated to the test. According to engagement management best pract...

Q2
hard

After completing a penetration test, the tester is preparing the final report. The client asks the tester to remove a critical finding from the report...

Q3
hard

A client requests a penetration test of their environment but insists that only two IT administrators know about the test. The security operations cen...

Q4
medium

A penetration tester is about to begin an assessment of a cloud-hosted application. Before launching any scans, which document should the tester obtai...

Q5
easy

Which section of a penetration test report is specifically written for non-technical stakeholders such as executives and summarizes risk exposure and ...

Q6
easy

Which document formally defines the boundaries, objectives, and rules of engagement for a penetration test and is signed before testing begins?

Q7
medium

A penetration tester is scoping an engagement for a financial services company. The client wants to test their web application but explicitly excludes...

Q8
hard

A penetration tester completes an engagement and discovers a critical remote code execution vulnerability in the client's public-facing application. T...

Q9
medium

A penetration testing team is conducting a red team engagement for a financial institution. The client wants to test their detection and response capa...

Q10
medium

A penetration tester has completed an engagement and is preparing the final deliverables. The rules of engagement require the tester to provide a reme...

Q11
easy

Which element of a penetration test report provides detailed technical evidence, such as screenshots and raw tool output, to support the identified fi...

Q12
hard

A penetration tester is asked to assess a third-party vendor's system that is connected to the client's network. The third-party vendor's system is no...

Q13
easy

Which type of penetration test provides the tester with full knowledge of the target environment, including network diagrams, source code, and credent...

Q14
medium

During a penetration test, the tester accidentally takes down a production web service while testing for vulnerabilities. What should the tester do IM...

Sign in to see all 14 questions

Create a free account to browse all questions — completely free during our launch phase.