Why Do Pen Testers Keep a Running Diary During Engagement?

A penetration tester keeps a running diary of the day-to-day engagement activity. Which of the following is the most likely explanation for keeping the diary?

  1. To facilitate post-engagement cleanup Source Reference Answer
  2. To monitor lessons learned
  3. To foster client acceptance
  4. To follow the data destruction process

Community Votes

A
67%
B
33%

67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the operational purpose of note-taking during an engagement; the trap is choosing 'lessons learned' instead of recognizing the diary as a record for reversing changes.

A running diary of day-to-day penetration testing activity is most commonly maintained to support post-engagement cleanup. While some debate whether it is for lessons learned, official exam consensus favors cleanup/restoration of systems.

Choosing B ('To monitor lessons learned') is the most common wrong answer because a diary can feed into lessons learned, but it is not the primary reason; the primary reason is to ensure all test-induced changes are cleaned up.

Community Discussion (7 comments)

kinny4000 👍 1 Selected: B
B. To monitor lessons learned A penetration testing diary helps track what worked, what didn't, and any unexpected behaviors. This can later be used in the Lessons Learned report. To facilitate post engagement cleanup, the steps taken will be recorded more formally, to avoid any problems if the tester quits or leaves unexpectedly.
fecffa8 👍 1
Its a toss up between A and B. I'm leaning towards B. From the cert master Taking Notes Another important part of the penetration test that can aid you during reporting (and after) is note taking. For example, note taking can help you keep track of additional details that occurred during the activities that you do not want to miss mentioning in the report. Alternatively, if after some time and other activities you are asked about this engagement in particular, you can refer back to your notes for any additional information that you may need. It will be important to tailor your note taking depending on your needs and the client’s. As this section is usually for internal use, it tends to be more flexible in regards to the needs of each penetration testing team, unlike the next section which is commonly tailored to a particular industry.
IamBlackFire 👍 1 Selected: A
Lesson Learned isn't duty for penetration tester; as the CompTIA Security+ 701 docet.
AnnoyingIAGuy 👍 2 Selected: A
A. After a long period of testing, it is easy to forget your steps and miss something during cleanup. Lessons learned will completely rely on end results. Not notes you kept in a diary.
uselessscript 👍 1 Selected: A
A penetration tester keeps day-to-day engagement activity documented to ensure that all engagement activities are cleaned up.
wdmssk 👍 1 Selected: B
The diary can assist in cleanup, but it is not primarily maintained for that purpose. The best explanation for keeping such a diary is "To monitor lessons learned", as it supports continuous improvement and tracking of methods throughout the engagement.
mat22 👍 3
Correct answer is A. Keeping a running diary of the day-to-day engagement activity helps the penetration tester track and document all actions, observations, and findings during the engagement. It provides a detailed record of all activities conducted, which helps in systematically cleaning up any changes made during the testing. This includes removing test data, reversing configuration changes, and ensuring that no residual access or impact remains.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A running diary provides an auditable trail of every action taken, including configurations changed, files created, and credentials used. This trail is essential for post-engagement cleanup because testers must restore systems to their pre-test state. Without the diary, the tester might miss artifacts or changes that could disrupt the client. CompTIA's suggested answer and the majority vote support A.

Why the Other Options Are Wrong

C ('To foster client acceptance') and D ('To follow the data destruction process') are clearly not the primary reasons for keeping a diary. B ('To monitor lessons learned') is a valuable outcome but comes from analyzing the engagement afterward, not from maintaining a day-to-day running diary. The diary is primarily a working record for cleanup and restoration, not a lessons-learned document.

Community Comment Notes

Comment [1] directly supports A, explaining that a detailed record helps systematically clean up changes made during testing. Comment [2] reinforces this by noting that after a long engagement, testers can easily forget steps and miss cleanup items. Comment [3] argues for B, but the majority and the suggested answer favor A. Comment [5] adds that lessons learned is not the penetration tester's duty per CompTIA Security+, making B less likely.

Official Reference

Exam Strategy

When you see questions about note-taking/diary, think 'post-engagement' phases: cleanup and reporting. Eliminate broad-sounding answers like 'lessons learned' if the question asks about the most likely explanation for keeping a running diary during the engagement.

Related Analysis

← Back to PT0-002 Study Guide