Free CompTIA PenTest+ practice — 6 questions on Engagement Management, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Engagement Management
During an authorized external network penetration test, the tester discovers clear indicators that a threat actor unrelated to the engagement currently has an active foothold on a client web server (an unfamiliar reverse shell beaconing to an unknown external IP). What is the MOST appropriate immediate action?
The RoE defines emergency escalation contacts and procedures for critical, time-sensitive findings such as an active third-party compromise. This must be reported immediately regardless of the original test scope because it represents ongoing harm to the client.
Question 2 of 6 · Engagement Management
A signed SOW for an external assessment explicitly excludes social engineering as an authorized technique. While researching the target, the tester discovers that an unrelated marketing vendor recently ran a phishing simulation against the same employees, and a set of harvested credentials from that campaign is posted on an internal wiki page the tester can access. Using these credentials would grant immediate administrative access to the domain. What should the tester do?
The exposed credentials resulted from an out-of-scope technique (social engineering), regardless of who performed it. The correct action is to document the exposure as a legitimate finding while seeking written scope-change authorization before exploiting it further, preserving both legal protection and engagement integrity.
Question 3 of 6 · Engagement Management
A consulting firm signs a single legal agreement with a long-term retainer client that establishes general terms, liability limitations, indemnification, and payment terms governing all future penetration testing engagements over the next three years. Individual engagements will each have their own scope and price detailed separately. Which document was executed?
An MSA is the umbrella legal contract that establishes recurring terms and conditions governing future work between two parties, allowing subsequent individual projects to be authorized through a lightweight SOW.
Question 4 of 6 · Engagement Management
A client requires that all vulnerability scanning traffic originate from a single statically assigned source IP address and occur only between 22:00 and 04:00 local time to avoid triggering SOC alerts and impacting production systems. In which document should these specific operational parameters be formally recorded before testing begins?
The RoE captures granular technical and operational constraints such as approved source IPs, testing windows, permitted techniques, and escalation contacts.
Question 5 of 6 · Engagement Management
What is the primary purpose of establishing 'goal reprioritization' criteria during the pre-engagement phase of a penetration test?
Goal reprioritization defines in advance the triggers — such as discovery of a critical vulnerability or active compromise — under which the team and client agree to communicate immediately and potentially shift testing priorities rather than proceeding blindly per the original plan.
Question 6 of 6 · Engagement Management
Three weeks after delivering the final penetration test report, the client remediates the critical findings and asks the testing firm to verify the vulnerabilities have been properly fixed. According to standard engagement lifecycle practices, what must occur before this verification work begins?
A retest is a distinct engagement activity requiring its own agreed scope, cost, and timeline, formalized through a new or amended SOW, even if the target environment is unchanged, since the original engagement's authorization window has typically ended.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.