CompTIA PenTest+ (PT0-003)Engagement ManagementMedium
A penetration testing contract requires that all client data, including cracked password hashes recovered with hashcat and any captured credentials, be securely wiped from the testing firm's systems within 30 days of final report delivery. This requirement is most likely found in which part of the engagement documentation?
- AA data handling and destruction clause in the MSA or SOW
- BThe Rules of Engagement testing window
- CThe executive summary of the final report
- DThe OWASP Testing Guide methodology section
Show answer & explanationAnswer & explanation
Correct answer: A. A data handling and destruction clause in the MSA or SOW
Data handling and destruction requirements are contractual obligations typically written into the MSA or SOW, specifying how long sensitive data (including cracked credentials) may be retained and how it must be sanitized after the engagement ends. This protects the client from lingering exposure of sensitive artifacts.
Why the other options are wrong
- B. The testing window in the RoE defines when active testing can occur, not data retention after the fact.
- C. The executive summary communicates findings to leadership, not data retention obligations.
- D. The OWASP Testing Guide is a technical testing methodology, not a contractual data handling requirement.
Data Handling/Destruction Clause
A contractual provision requiring the testing firm to securely retain and eventually destroy client data, including credentials and hashes, within a specified timeframe after the engagement.
- Usually located in the MSA or SOW
- Covers cracked hashes, captured credentials, and scan data
- Protects the client from long-term exposure of sensitive artifacts
Memory trick: Deliver, Destroy, reDo (retest), Done: the four D's after the report.