Why Do Pen Testers Keep a Running Diary During Engagement?
A penetration tester keeps a running diary of the day-to-day engagement activity. Which of the following is the most likely explanation for keeping the diary?
Community Votes
67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the operational purpose of note-taking during an engagement; the trap is choosing 'lessons learned' instead of recognizing the diary as a record for reversing changes.
A running diary of day-to-day penetration testing activity is most commonly maintained to support post-engagement cleanup. While some debate whether it is for lessons learned, official exam consensus favors cleanup/restoration of systems.
Choosing B ('To monitor lessons learned') is the most common wrong answer because a diary can feed into lessons learned, but it is not the primary reason; the primary reason is to ensure all test-induced changes are cleaned up.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A running diary provides an auditable trail of every action taken, including configurations changed, files created, and credentials used. This trail is essential for post-engagement cleanup because testers must restore systems to their pre-test state. Without the diary, the tester might miss artifacts or changes that could disrupt the client. CompTIA's suggested answer and the majority vote support A.Why the Other Options Are Wrong
C ('To foster client acceptance') and D ('To follow the data destruction process') are clearly not the primary reasons for keeping a diary. B ('To monitor lessons learned') is a valuable outcome but comes from analyzing the engagement afterward, not from maintaining a day-to-day running diary. The diary is primarily a working record for cleanup and restoration, not a lessons-learned document.Community Comment Notes
Comment [1] directly supports A, explaining that a detailed record helps systematically clean up changes made during testing. Comment [2] reinforces this by noting that after a long engagement, testers can easily forget steps and miss cleanup items. Comment [3] argues for B, but the majority and the suggested answer favor A. Comment [5] adds that lessons learned is not the penetration tester's duty per CompTIA Security+, making B less likely.Official Reference
Exam Strategy
When you see questions about note-taking/diary, think 'post-engagement' phases: cleanup and reporting. Eliminate broad-sounding answers like 'lessons learned' if the question asks about the most likely explanation for keeping a running diary during the engagement.