mediumMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A client hires a penetration testing firm to…
A client hires a penetration testing firm to assess a web application. The client uses a third-party content delivery network (CDN) for static assets and explicitly wants to exclude the CDN infrastructure from testing. In which document should this restriction be formally documented?
⚠ Common exam trap
Test-takers frequently confuse the ROE with the SOW, assuming the SOW is the catch-all document for all restrictions, but the ROE is specifically designed for operational boundaries and constraints in penetration testing engagements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rules of Engagement (ROE)
The Rules of Engagement (ROE) document is the correct place to formally document restrictions such as excluding the CDN infrastructure from testing. The ROE defines the scope, boundaries, and specific constraints for the penetration test, including which IP ranges, domains, or systems are off-limits. This ensures the testing team does not inadvertently target the third-party CDN, which could violate contractual agreements or cause unintended disruptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Statement of Work (SOW)
Why it's wrong here
The Statement of Work defines the deliverables, timeline, assumptions, and pricing for the engagement, but it generally stays at a high level of scope. It would not normally enumerate individual technical exclusions such as 'do not test the CDN' because that level of operational detail belongs in the Rules of Engagement.
- ✗
Non-Disclosure Agreement (NDA)
Why it's wrong here
The Non-Disclosure Agreement is a confidentiality contract that governs how the penetration testing firm handles client data, findings, and trade secrets. It has no bearing on which hosts are in scope or whether a CDN is off-limits, so it cannot be the document that records a technical testing restriction.
- ✗
Master Services Agreement (MSA)
Why it's wrong here
The Master Services Agreement establishes ongoing legal and business terms such as liability limits, indemnification, insurance, and payment obligations across multiple engagements. Since it is designed to cover the overall client-vendor relationship rather than a single assessment, a project-specific exclusion of a CDN would be documented at the engagement level, not in the MSA.
- ✓
Rules of Engagement (ROE)
Why this is correct
The Rules of Engagement is the document that explicitly authorizes and constrains the technical execution of the assessment, including in-scope IP addresses, allowed testing times, emergency contacts, and specific exclusions like the CDN. It bridges the gap between contractual scope and the actual commands and techniques used, and it is the document the tester consults to determine exactly what may or may not be touched.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.