Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A client requests a penetration test of their…

A client requests a penetration test of their production environment that includes critical financial transaction systems. The client is concerned about potential service disruptions. Which of the following should the tester include in the Rules of Engagement to address this concern?

⚠ Common exam trap

Watch out — candidates often confuse 'scope exclusion' (Option C) with a valid risk mitigation strategy, but the PT0-002 exam expects testers to include controls like stop-loss conditions to enable safe testing of in-scope critical systems rather than excluding them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A 'stop loss' condition that requires immediate termination of testing if system metrics exceed defined thresholds

A 'stop loss' condition is a standard mechanism in Rules of Engagement (RoE) that defines specific system metrics (e.g., CPU utilization > 90%, memory usage > 80%, or transaction latency > 500ms) which, when exceeded, require immediate termination of testing. This directly addresses the client's concern about service disruptions in the production environment by providing a safety threshold that prevents the penetration test from causing performance degradation or outages in critical financial transaction systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The tester will only use passive reconnaissance techniques

    Why it's wrong here

    Passive reconnaissance gathers OSINT, DNS records, certificate transparency, and metadata, but it never sends a single packet to the target. Because vulnerabilities like SQL injection, broken access control, or unpatched services cannot be confirmed without actively interacting with the application, a passive-only test would fail to validate whether discovered issues are truly exploitable. This approach may be appropriate for a threat footprint assessment, but it is insufficient for a production penetration test that must prove business risk and provide actionable remediation guidance.

  • A 'stop loss' condition that requires immediate termination of testing if system metrics exceed defined thresholds

    Why this is correct

    A stop-loss condition is a predefined threshold on system metrics (e.g., CPU utilization, memory consumption, request latency, or error rate) that, when exceeded, triggers immediate termination of all active testing. In a production environment, exploit payloads, credential-stuffing loops, or vulnerability scanners can inadvertently cause a self-inflicted denial of service by exhausting connection pools, filling disk queues, or saturating bandwidth. Defining these thresholds in the rules of engagement gives the tester a clear, objective tripwire to protect availability before damage occurs, while still allowing aggressive testing up to that limit.

  • Exclude all financial transaction systems from the scope of testing

    Why it's wrong here

    Excluding every financial transaction system from scope would be a critical oversight if the client's objective is to test the security of those exact assets. A penetration test is designed to validate the effectiveness of security controls on the systems that matter most, and financial transaction systems typically process the highest-value data and present the largest attack surface. Instead of a blanket exclusion, the tester should include these systems with safeguards such as using synthetic transaction records, limiting load to off-peak hours, or testing in a replica staging environment. A scope that systematically removes the most sensitive components will provide a false sense of security and likely violate compliance requirements that mandate testing these systems.

  • The client must provide a service level agreement (SLA) to the tester

    Why it's wrong here

    An SLA (service level agreement) is a contractual commitment from a service provider kepada a customer, not something a client hands to a penetration tester to define testing parameters. Penetration testing engagements are governed by a statement of work, rules of engagement, and an authorization letter, which specify targets, allowed techniques, timing, and emergency contacts, not uptime guarantees from the client. Asking the client to provide an SLA to the tester inverts the contracting relationship and does nothing to define safe testing boundaries. The tester, not the client, typically offers commitments around response times and reporting, but those are part of the commercial agreement, not a prerequisite for testing.

About these practice questions

This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.