Courseiva
mediumMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A client hires a penetration testing firm to…

A client hires a penetration testing firm to assess a web application. The client uses a third-party content delivery network (CDN) for static assets and explicitly wants to exclude the CDN infrastructure from testing. In which document should this restriction be formally documented?

⚠ Common exam trap

Test-takers frequently confuse the ROE with the SOW, assuming the SOW is the catch-all document for all restrictions, but the ROE is specifically designed for operational boundaries and constraints in penetration testing engagements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Rules of Engagement (ROE)

The Rules of Engagement (ROE) document is the correct place to formally document restrictions such as excluding the CDN infrastructure from testing. The ROE defines the scope, boundaries, and specific constraints for the penetration test, including which IP ranges, domains, or systems are off-limits. This ensures the testing team does not inadvertently target the third-party CDN, which could violate contractual agreements or cause unintended disruptions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Statement of Work (SOW)

    Why it's wrong here

    The Statement of Work defines the deliverables, timeline, assumptions, and pricing for the engagement, but it generally stays at a high level of scope. It would not normally enumerate individual technical exclusions such as 'do not test the CDN' because that level of operational detail belongs in the Rules of Engagement.

  • Non-Disclosure Agreement (NDA)

    Why it's wrong here

    The Non-Disclosure Agreement is a confidentiality contract that governs how the penetration testing firm handles client data, findings, and trade secrets. It has no bearing on which hosts are in scope or whether a CDN is off-limits, so it cannot be the document that records a technical testing restriction.

  • Master Services Agreement (MSA)

    Why it's wrong here

    The Master Services Agreement establishes ongoing legal and business terms such as liability limits, indemnification, insurance, and payment obligations across multiple engagements. Since it is designed to cover the overall client-vendor relationship rather than a single assessment, a project-specific exclusion of a CDN would be documented at the engagement level, not in the MSA.

  • Rules of Engagement (ROE)

    Why this is correct

    The Rules of Engagement is the document that explicitly authorizes and constrains the technical execution of the assessment, including in-scope IP addresses, allowed testing times, emergency contacts, and specific exclusions like the CDN. It bridges the gap between contractual scope and the actual commands and techniques used, and it is the document the tester consults to determine exactly what may or may not be touched.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.