mediumMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A client engages a penetration testing firm to…
A client engages a penetration testing firm to evaluate the security of their internal network. During the scoping meeting, the client states that they use a network access control (NAC) solution that might block the tester's machine if it is connected to the internal network without prior authorization. Which of the following should be included in the rules of engagement to address this potential issue?
⚠ Common exam trap
Many exam-takers assume disabling NAC (Option A) is the simplest solution, but the exam tests whether you understand that altering security controls during a test can invalidate the assessment's realism and that proper scoping requires minimal disruption to the client's environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a clause requiring the client to whitelist the tester's MAC address in the NAC policy before testing.
Whitelisting the tester's MAC address in the NAC policy allows the tester's machine to connect to the internal network without being blocked, while keeping the NAC solution active for other devices. This approach preserves the real-world security posture of the client's environment and ensures the tester can perform internal network assessments as scoped. It is a standard practice in penetration testing to request MAC address whitelisting to avoid false positives from NAC enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include a requirement that the client disables NAC during the testing window.
Why it's wrong here
Disabling NAC globally for the entire testing window removes the access control boundary for every endpoint, not just the tester's device. This would leave the client's network open to unauthorized or non-compliant devices during the test, significantly increasing risk and potentially violating compliance requirements. A proper rule of engagement should grant the tester access through a narrow, controlled exception such as a MAC whitelist, not by disabling the security control entirely, which is an unreasonable and disproportionate request.
- ✗
State that the tester will not connect to the internal network and will only test externally.
Why it's wrong here
Stating that the tester will only perform external testing directly contradicts the client's explicit request for an internal network assessment, so the engagement would fail to meet its core objective. Without internal connectivity, the tester cannot evaluate internal segmentation, host hardening, or how NAC would react to an unauthorized device from inside the network. The rule of engagement should define how the tester is granted authorized internal access, not avoid the internal network altogether, as that would render the test out of scope.
- ✗
Specify that the tester will bypass NAC as part of the test objectives.
Why it's wrong here
Specifying that the tester will bypass NAC as a test objective conflates the practical need for authorized access with the testing goal of assessing NAC security. A bypass attempt might be a legitimate separate objective, but it should be explicitly agreed upon in the scope and rules of engagement, not used as the method to gain initial network access. Furthermore, attempting to bypass NAC on an unapproved basis could cause network disruptions or legal issues, whereas a pre-authorized whitelist provides a clean, controlled way for the tester to connect before any bypass testing begins.
- ✓
Add a clause requiring the client to whitelist the tester's MAC address in the NAC policy before testing.
Why this is correct
Adding a clause that requires the client to whitelist the tester's MAC address in the NAC policy before testing is the correct approach because it authorizes the specific testing device while preserving the security posture for all other devices. NAC policies typically use MAC authentication or 802.1X to enforce compliance, and a pre-whitelisted MAC allows the tester's device to avoid the quarantined or blocked state that an unknown device would receive. This should be arranged in advance to prevent connectivity delays during the test window and is a standard, low-risk practice for authorized penetration testing engagements.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.