easyMultiple Choice
PT0-002 Practice Question: A client requests a penetration test of their web…
A client requests a penetration test of their web application, but they want to exclude all third-party APIs from the scope. Where should this exclusion be documented?
⚠ Common exam trap
CompTIA often tests the misconception that scope exclusions belong in the final report or executive summary because candidates confuse 'what was tested' with 'what was excluded,' but the ROE is the only document that governs the testing parameters before execution begins.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rules of Engagement
The Rules of Engagement (ROE) document is the authoritative source for defining the scope, boundaries, and constraints of a penetration test, including explicit exclusions such as third-party APIs. This document is established during the planning and scoping phase to ensure both the client and the testing team agree on what is and is not in scope, preventing legal or operational issues. Without documenting the exclusion in the ROE, the tester might inadvertently interact with the third-party APIs, violating the agreement and potentially causing service disruptions or legal liabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Rules of Engagement
Why this is correct
The Rules of Engagement (RoE) is the authoritative contract section that legally defines the testing boundaries, including authorized systems, testing windows, and explicit scope exclusions. Because it establishes the formal limits of what the penetration tester may access and perform, any out-of-scope assets or prohibited techniques must be documented here to prevent misunderstandings and legal liability. This makes the RoE the only correct location for recording scope exclusions.
- ✗
Executive Summary
Why it's wrong here
The Executive Summary is a high-level, non-technical narrative written after the assessment concludes, intended for board members and executives who need a concise overview of the overall security posture and business risk. It deliberately omits granular operational details such as which IP ranges or endpoints were excluded from testing, as those specifics reside in the technical engagement documentation. Scope exclusions are neither summarized nor suitable for this audience-oriented section.
- ✗
Findings Report
Why it's wrong here
The Findings Report is a post-assessment deliverable that catalogs each discovered vulnerability with technical evidence, proof-of-concept steps, CVSS scores, and affected assets. Its purpose is to communicate what was actually found and tested, not to define what was intentionally left out of the initial testing scope. Since scope exclusions are established before testing commences, placing them in this report would be chronologically and functionally inappropriate.
- ✗
Remediation Plan
Why it's wrong here
The Remediation Plan is an actionable, forward-looking document that provides prioritized steps, code fixes, configuration changes, and responsible parties to mitigate vulnerabilities that were already identified. It assumes testing has taken place and focuses on resolving weaknesses, not on documenting the initial contractual boundaries of the engagement. Scope exclusions are pre-test constraints agreed upon beforehand, so the Remediation Plan is the wrong artifact for them.
Go deeper
Related to this question
Learn chapter
Re-Testing and Validation Testing
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.