CompTIA PenTest+ (PT0-003)Engagement ManagementEasy
During an active engagement, a tester's nmap scan against an in-scope subnet triggers the client's intrusion prevention system, which blocks the tester's IP address and pages the client's SOC on-call engineer. Per the Rules of Engagement, what should the tester do next?
- ASwitch to a different source IP and continue scanning without notifying anyone
- BEscalate directly to the client's CEO to report the blocked IP
- CStop the engagement entirely and wait for the client to reach out
- DImmediately contact the designated technical point of contact to deconflict the activity
Show answer & explanationAnswer & explanation
Correct answer: D. Immediately contact the designated technical point of contact to deconflict the activity
The RoE should define a communication/escalation path with a designated technical point of contact for deconfliction when defensive tools react to authorized testing. Contacting this person confirms the activity is expected and prevents unnecessary incident response resources from being consumed.
Why the other options are wrong
- A. Evading detection without notification violates the RoE and could be mistaken for a real attack.
- B. Escalating to the CEO bypasses the technical point of contact designated for operational issues.
- C. Halting entirely is unnecessary and not typically required just because a scan was blocked.
Deconfliction / Communication Plan
A defined escalation path in the RoE identifying who to contact when testing activity triggers alerts or is mistaken for a real attack.
- Prevents wasted incident response effort on authorized activity
- Should list names, roles, and contact methods (phone/email)
- Used whenever defensive controls react unexpectedly to testing
Memory trick: When alarms ring, call the RoE contact, don't go silent or go to the top.