mediumMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A client requests a penetration test of their…
A client requests a penetration test of their internal network. During scoping, the tester learns that the client uses a managed security service provider (MSSP) that monitors all network traffic. The client does not want the MSSP to be informed about the test. What is the most appropriate action for the tester to take?
⚠ Common exam trap
Candidates often assume client confidentiality overrides all other considerations, but the PT0-002 exam emphasizes that penetration testing must not cause unintended operational disruptions or violate third-party agreements, making coordination with the MSSP a mandatory scoping step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Advise the client to inform the MSSP about the scheduled test and coordinate a maintenance window or exclusion list
Failing to inform the MSSP could trigger automated incident response actions (e.g., IPS blocking, SIEM alerting, or even network isolation) that disrupt the test and potentially cause false-positive security incidents. Coordinating a maintenance window or exclusion list ensures the MSSP's monitoring tools (like Snort, Suricata, or proprietary NDR) do not interfere with legitimate test traffic, preserving both test integrity and the client's operational security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Proceed with the test without informing the MSSP, as the client has requested confidentiality
Why it's wrong here
Performing the test without informing the MSSP ignores that penetration test traffic often mirrors known attack patterns, which the MSSP's SIEM and EDR will flag and potentially quarantine. Even if the client demands confidentiality, that does not waive the MSSP's legal or contractual duty to respond to suspicious activity, creating false positives, service interruptions, and possible breach of the provider's monitoring terms. Thus, the test's integrity and the client's operations are both compromised.
- ✗
Include a clause in the rules of engagement that holds the tester harmless for any disruptions caused by the MSSP's monitoring
Why it's wrong here
A hold harmless clause shifts liability for damage between the client and tester, but it cannot instruct or disable the MSSP's automated security controls. The MSSP's detection tools (e.g., endpoint detection and response, firewalls, IPS) are bound by their own logic and will still blacklist, block, or isolate test traffic. Additionally, this clause does nothing to prevent the false-positive alerts that will consume the SOC's time and the client's incident response resources.
- ✓
Advise the client to inform the MSSP about the scheduled test and coordinate a maintenance window or exclusion list
Why this is correct
Advising the client to inform the MSSP and coordinate a maintenance window or exclusion list is the correct approach because it allows the MSSP to create a temporary allow list for the test's source IPs, domains, and tool signatures. This suppresses expected alerts, prevents unnecessary incident response, and ensures the SOC can distinguish legitimate test traffic from true threats. It also establishes a deconfliction contact so both parties can respond quickly if unexpected activity arises, aligning with standard scoping and rules of engagement practices.
- ✗
Perform the test only after hours to minimize the chance of the MSSP detecting the test activity
Why it's wrong here
Running the test after hours is ineffective because MSSP teams use 24/7 monitoring with automated analytics that do not rest; malicious-looking test traffic will still trigger alerts and potentially be auto-contained by EDR or network controls. The timing only reduces user impact, not detection, and it often means fewer client staff are available to approve emergency actions or adjust the exclusion list. Consequently, the test can be halted by an automated response even during off-peak hours, leaving results incomplete.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.