Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA PT0-003 Exam - Topic 1 Question 34 Discussion

A tester is finishing an engagement and needs to ensure that artifacts resulting from the test are safely handled. Which of the following is the best procedure for maintaining client data privacy?
B) Securely destroy or remove all engagement-related data from testing systems.
A) Remove configuration changes and any tools deployed to compromised systems.
C) Search through configuration files changed for sensitive credentials and remove them.
D) Shut down C2 and attacker infrastructure on premises and in the cloud.

CompTIA PT0-003 Exam - Topic 1 Question 34 Discussion

Actual exam question for CompTIA's PT0-003 exam
Question #: 34
Topic #: 1
[All PT0-003 Questions]

A tester is finishing an engagement and needs to ensure that artifacts resulting from the test are safely handled. Which of the following is the best procedure for maintaining client data privacy?

Show Suggested Answer Hide Answer
Suggested Answer: B

At the end of a penetration test, handling sensitive data properly ensures compliance with legal, regulatory, and ethical guidelines.

Securely destroy or remove all engagement-related data (Option B):

Ensures confidentiality of test results.

Prevents unauthorized access to client information.

Methods include secure wiping tools (shred, sdelete), and encrypted storage deletion.


Incorrect options:

Option A (Remove configuration changes): Necessary but does not ensure complete data destruction.

Option C (Search for sensitive credentials): Important but does not address all artifacts.

Option D (Shut down C2 infrastructure): Important for OPSEC but does not address client data privacy.

Contribute your Thoughts:

0/2000 characters
Jodi
4 hours ago
I think option B is the best. Data privacy is crucial.
upvoted 0 times
...
Hildegarde
5 days ago
D is good for security, but it doesn't address data privacy directly.
upvoted 0 times
...
Alesia
10 days ago
Wait, are we really trusting all these methods? Sounds sketchy.
upvoted 0 times
...
Odette
16 days ago
C seems risky, what if you miss something?
upvoted 0 times
...
Rosalind
2 months ago
I think A is important too, but B is more comprehensive.
upvoted 0 times
...
Linette
2 months ago
B is definitely the way to go. Data privacy is key!
upvoted 0 times
...
Wenona
3 months ago
D seems more about shutting down infrastructure rather than handling data privacy directly. I think B is definitely the best choice here.
upvoted 0 times
...
Viki
3 months ago
I’m a bit confused about C. It mentions searching through files, but I feel like that might not be enough to ensure complete privacy.
upvoted 0 times
...
Cordie
3 months ago
I remember a practice question where we discussed the importance of removing sensitive data, so I lean towards B too, but A seems relevant as well.
upvoted 0 times
...
Eladia
3 months ago
I think option B makes the most sense since securely destroying data is crucial for privacy. But I'm not entirely sure if that's the only step needed.
upvoted 0 times
...

Save Cancel