mediumMultiple Choice
PT0-002 Practice Question: A client requests a penetration test of a new…
A client requests a penetration test of a new mobile application that is still in development and only accessible on a test server behind the corporate VPN. The tester should include which of the following in the scope?
⚠ Common exam trap
The trap here is that candidates may mistakenly include the corporate VPN infrastructure or production servers, thinking they are necessary for a comprehensive test, but the scope must be strictly limited to the components specified by the client to avoid unauthorized testing and scope creep.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Only the test server and the mobile application client
The scope of a penetration test for an application still in development should be limited to the test server and the mobile application client. This ensures the assessment focuses on the application's security posture without including production systems that are not yet live or the corporate VPN infrastructure, which is typically out of scope unless explicitly requested. The tester should only evaluate the components directly relevant to the application's functionality and security during development.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The production servers hosting the app when it goes live
Why it's wrong here
Testing production servers lies outside the agreed scope, which covers only the development app on the VPN-restricted test server. It is tempting because production testing is a legitimate goal, and would be correct once the app goes live and the client authorises those hosts in writing.
- ✓
Only the test server and the mobile application client
Why this is correct
Scope should cover only the in-development test server and the mobile client under test. Production systems and the wider corporate VPN are excluded because the app is unreleased and confined to that test environment, matching the stem's limited-access constraint.
- ✗
The corporate VPN infrastructure
Why it's wrong here
The VPN is shared corporate infrastructure, not the application under test; probing it exceeds the agreed target and risks disrupting production services. It is tempting because the app is reachable only through that tunnel, and VPN testing would be in scope if the client explicitly requested infrastructure assessment alongside the application.
- ✗
All third-party APIs used by the application
Why it's wrong here
Third-party APIs sit outside the client's authorisation boundary; the client controls only the application and its test server, so testing external services requires separate written permission from each provider. Including them is tempting because integration flaws often surface there, and it would be correct if the client owned or had authorisation over those APIs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.