Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A client requests a penetration test of their…

A client requests a penetration test of their network and provides a list of IP addresses. During scoping, the tester notices that several IP addresses belong to a major cloud service provider. What should the tester do FIRST before including those IP addresses in the test?

⚠ Common exam trap

CompTIA often tests the misconception that a client-provided IP list is sufficient authorization, but the trap here is that cloud IPs require additional verification and written permission from the provider due to multi-tenant risks and legal boundaries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Ask the client to verify ownership and obtain written authorization from the cloud provider if needed

Testing cloud provider IP addresses without explicit authorization violates the cloud provider's terms of service and could be considered unauthorized access, potentially leading to legal action. The tester must first verify that the client actually owns those IPs (e.g., via ARIN WHOIS or cloud provider documentation) and obtain written authorization from the cloud provider, as the provider's shared infrastructure means the tester's traffic could impact other tenants. This aligns with the PT0-002 scoping requirement to confirm all targets are within the authorized boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Proceed with testing since the client provided the IP addresses

    Why it's wrong here

    Proceeding solely because the client supplied a list of IP addresses is insufficient, as the client may not have legal ownership or contractual permission to have those systems tested. If any of those addresses route to cloud resources, the underlying cloud provider (e.g., AWS, Azure) is a separate party whose Acceptable Use Policy and terms of service typically require prior written authorization before penetrative activities. Initiating any testing without verified authorization could constitute a violation of the Computer Fraud and Abuse Act or equivalent legislation in other jurisdictions, exposing the tester to criminal and civil liability regardless of the client's assertions.

  • Ask the client to verify ownership and obtain written authorization from the cloud provider if needed

    Why this is correct

    The correct approach is to treat cloud-hosted assets as potentially owned or operated by a third party, even if the client claims they belong to their organization. The tester should request documentation proving ownership, such as cloud account identifiers, virtual network/subnet details, or a letter from the cloud provider explicitly authorizing penetration testing of the specified IP ranges. Written authorization from both the client and, when necessary, the cloud provider protects the tester against legal action, ensures the provider's security monitoring does not flag the activity as malicious, and keeps the test within the boundaries of the provider's testing policies (e.g., AWS's penetration testing policy, Azure's security testing guidelines).

  • Exclude the cloud IP addresses from the scope without further discussion

    Why it's wrong here

    Excluding the cloud IP addresses without further discussion is flawed because those assets might genuinely belong to the client and be part of the intended test scope, even if they are hosted on infrastructure owned by a cloud provider. Prematurely removing them could leave critical, externally facing systems untested and create a false sense of security, as the client would believe the penetration test was complete but the cloud footprint was never assessed. Additionally, the tester's duty is to validate scope collaboratively with the client through the rules of engagement; unilateral scope reduction without documented justification is both unprofessional and operationally incomplete.

  • Perform a quick port scan to determine if the IPs are responsive before deciding

    Why it's wrong here

    Performing a preliminary port scan to 'see if they respond' is itself an unauthorized action, as network scanning is considered active reconnaissance and can be construed as a precursor to an intrusion attempt under statutes like the CFAA. Even if the scan is limited to determining reachability, it violates cloud provider terms of service and may trigger automated abuse alerts, potentially resulting in the client's entire account being suspended or investigated. As a penetration tester, all testing activities—including passive or low-impact probes—must occur only after proper authorization is verified and documented; there is no safe 'recon-only' shortcut that bypasses legal due diligence.

About these practice questions

One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.