Courseiva
easyMultiple Choice

PT0-002 Practice Question: A client wants a penetration test of their…

A client wants a penetration test of their internal network. They are concerned about causing any disruption to the production systems. The tester should include which of the following in the rules of engagement to address this concern?

⚠ Common exam trap

The trap here is that candidates may mistakenly think listing tools or disabling antivirus is necessary for a thorough test, but the core concern is disruption prevention, which is directly addressed by the testing window and emergency stop clause in the RoE.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A clear definition of the testing window and contact information for emergency stop

A clearly defined testing window with emergency stop contact information directly addresses the client's concern about production disruption. This ensures the tester can immediately halt activities if any instability is detected, aligning with the principle of minimizing operational impact during a penetration test.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A list of all tools that will be used during the test

    Why it's wrong here

    A pre-published inventory of testing tools addresses what will be used, but it says nothing about when the test runs or how the client can halt it if a production system starts failing. From an operational risk standpoint, the client's concern is immediate service disruption, not tool selection; a tool list may even reveal Tactics, Techniques, and Procedures (TTPs) without granting any control over the engagement's real-time impact. The absence of a defined time window or stop mechanism means the client still has no way to prevent or mitigate an outage caused by active exploitation or scanning.

  • ✓

    A clear definition of the testing window and contact information for emergency stop

    Why this is correct

    Defining the testing window creates a mutually agreed time boundary that limits the potential blast radius of unintended disruption, while the emergency stop contact gives the client a direct, immediate channel to halt all active testing if systems become unstable. This is a core element of the Rules of Engagement (RoE) and is standard practice in penetration testing, because even scheduled scans can trigger resource exhaustion or trip failover mechanisms. The contact must be reachable 24/7 during the engagement, and the emergency stop procedure should include a clear order to cease all active tools, drop sessions, and confirm shutdown. This directly aligns with the client's stated concern by providing both temporal constraints and a real-time abort capability.

  • ✗

    A requirement for the client to disable their antivirus software

    Why it's wrong here

    Requiring the client to disable antivirus or endpoint protection is unsafe and operationally counterproductive: it intentionally weakens the client's security posture for the duration of the test, exposing the organization to unrelated malware or attacker activity that the test itself is not responsible for. Modern EDR/AV platforms also cannot simply be 'turned off' in many enterprise environments without tripping tamper protection, and doing so would create a false test environment that does not reflect production resilience. The client's worry is about service disruption, not about whether AV will flag the tester's tools; if anything, the tester and the client should coordinate on how to handle AV-generated alerts rather than eliminate the control.

  • ✗

    A statement that the tester will not be liable for any damages

    Why it's wrong here

    A blanket liability disclaimer attempts to shift legal risk, but it does nothing to prevent, detect, or mitigate service disruption during the test, which is the client's actual operational concern. In many jurisdictions, clauses that waive liability for gross negligence or intentional damage are unenforceable, and in a pentest engagement they are typically addressed in the master services agreement, not in an operational test plan. Even if the tester were fully insulated from legal consequences, that would not give the client a way to stop a disruptive scan or minimize downtime, so it is irrelevant to the request at hand. The correct way to manage disruption risk is through the Rules of Engagement, not through liability language.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.