Free Top CompTIA Pentest+ PT0-003 Actual Exam Questions - Question 4 Discussion

Question No. 4
A penetration tester cannot complete a full vulnerability scan because the client's WAF is blocking
communications. During which of the following activities should the penetration tester discuss this
issue with the client?
Select one option, then reveal solution.
US
SS
Sarah S.
2026-02-22

Maybe D fits best here since the WAF issue impacts multiple stakeholders, not just the tester or one team. Getting everyone on the same page can help decide the next steps properly.

0
SS
Sarah S.
2026-02-22

I’m thinking client acceptance (C) might be important here since that’s when you confirm the test scope and any known blockers like a WAF. Shouldn't this be cleared before testing starts?

0
YO
Yasir O.
2026-02-17

D The WAF blocking might affect multiple teams or project aspects, so aligning stakeholders early can prevent bigger issues down the line instead of just tweaking goals alone.

0
ML
Mason L.
2026-02-16

A/D? I’m thinking you’d want to sort this out as soon as the issue comes up, which feels like goal reprioritization (A). But maybe stakeholder alignment (D) too, since the WAF blocking could affect more than just goals—it impacts who needs to be involved in decisions or adjustments. Definitely not peer review or client acceptance since those are earlier or unrelated steps. The WAF issue is a blocker that requires quick discussion and possibly changing scope or rules of engagement.

0
TG
Tom G.
2026-01-31

Probably A, since adjusting goals fits when blockers like the WAF pop up mid-test.

0
JU
James U.
2026-01-30

A. It’s best to flag issues like WAF blocking during goal reprioritization since you might need to adjust the testing scope or methods based on what’s actually possible.

0
JU
James U.
2026-01-27

Maybe A, since reprioritizing goals fits when blockers come up during testing.

0
CE
Carlos E.
2026-01-23

I think it makes sense to bring this up during C, client acceptance. That’s when you talk through the scope and limitations with the client upfront. If a WAF is blocking scans, it’s a big deal that could alter what’s possible, so flagging it early helps avoid surprises later. Wouldn't waiting for alignment or reprioritization be too late since the scan is already blocked?

0
RZ
Rizwan Z.
2026-01-20

D, because stakeholders need to know blockers early for alignment.

0
RZ
Rizwan Z.
2026-01-16

A

0