Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A client requests a penetration test of a new…

A client requests a penetration test of a new mobile application that is still in development and only accessible on a test server behind the corporate VPN. The tester should include which of the following in the scope?

⚠ Common exam trap

The trap here is that candidates may mistakenly include the corporate VPN infrastructure or production servers, thinking they are necessary for a comprehensive test, but the scope must be strictly limited to the components specified by the client to avoid unauthorized testing and scope creep.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Only the test server and the mobile application client

The scope of a penetration test for an application still in development should be limited to the test server and the mobile application client. This ensures the assessment focuses on the application's security posture without including production systems that are not yet live or the corporate VPN infrastructure, which is typically out of scope unless explicitly requested. The tester should only evaluate the components directly relevant to the application's functionality and security during development.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The production servers hosting the app when it goes live

    Why it's wrong here

    Testing production servers lies outside the agreed scope, which covers only the development app on the VPN-restricted test server. It is tempting because production testing is a legitimate goal, and would be correct once the app goes live and the client authorises those hosts in writing.

  • ✓

    Only the test server and the mobile application client

    Why this is correct

    Scope should cover only the in-development test server and the mobile client under test. Production systems and the wider corporate VPN are excluded because the app is unreleased and confined to that test environment, matching the stem's limited-access constraint.

  • ✗

    The corporate VPN infrastructure

    Why it's wrong here

    The VPN is shared corporate infrastructure, not the application under test; probing it exceeds the agreed target and risks disrupting production services. It is tempting because the app is reachable only through that tunnel, and VPN testing would be in scope if the client explicitly requested infrastructure assessment alongside the application.

  • ✗

    All third-party APIs used by the application

    Why it's wrong here

    Third-party APIs sit outside the client's authorisation boundary; the client controls only the application and its test server, so testing external services requires separate written permission from each provider. Including them is tempting because integration flaws often surface there, and it would be correct if the client owned or had authorisation over those APIs.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.