easyMultiple Choice
PT0-002 Practice Question: A client wants a penetration test that includes…
A client wants a penetration test that includes social engineering attacks against employees. They request that the testing team not target the executive leadership team. What should be included in the rules of engagement to address this requirement?
⚠ Common exam trap
Many candidates confuse operational constraints (like volume or timing) with scoping exclusions, failing to recognize that only a direct list of excluded entities satisfies the requirement to avoid targeting a specific group.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A list of excluded users or groups, specifically the executive leadership team
The rules of engagement (RoE) must explicitly define the scope and boundaries of the test. Including a list of excluded users or groups, specifically the executive leadership team, ensures that social engineering attacks are not directed at them, directly addressing the client's requirement. This is a standard scoping practice in penetration testing to prevent unintended consequences and maintain legal and ethical compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A list of excluded users or groups, specifically the executive leadership team
Why this is correct
In social engineering engagements, the rules of engagement (RoE) must explicitly document any individuals or groups that are off-limits, such as executives, because compromising their accounts could have disproportionate business impact. This list ensures the testing team does not inadvertently target high-risk personnel, avoiding potential escalation, legal issues, or reputational damage. Without such an exclusion list, the penetration tester might phish the CEO or CFO, violating the client's implicit expectations and potentially causing real harm. Therefore, specifying excluded users is a critical scoping element that directly addresses target restrictions.
- ✗
The maximum number of phishing emails that can be sent
Why it's wrong here
While setting a cap on phishing email volume is a valid operational constraint to prevent overwhelming the client's email infrastructure and to keep the test within agreed boundaries, it does not define which individuals are protected from targeting. A volume limit can still allow all emails to be sent to executives if no exclusions are specified, meaning it fails to safeguard the executive leadership team. Thus, it controls attack intensity but not target scope, making it insufficient for the requirement of excluding specific groups.
- ✗
The time window for conducting social engineering activities
Why it's wrong here
Defining the allowable hours for social engineering activities, such as conducting phishing campaigns during business hours, is important for minimizing disruption and aligning with the client's operations, but it is a temporal constraint rather than a target-based one. Even with a restricted time window, the tester could still send emails to executives within that window, so it does nothing to identify or protect excluded personnel. The time window governs when attacks occur, not who may be attacked, so it cannot substitute for a list of excluded users.
- ✗
A description of the social engineering techniques that will be used
Why it's wrong here
Outlining the specific social engineering techniques to be used, such as pretexting, spear-phishing, or vishing, is essential for obtaining informed consent and ensuring the client understands the methods, but it describes the "how" rather than the "who." Even with a clear description of techniques, the tester might apply those techniques to the CEO unless an explicit exclusion list is provided. Technique descriptions define the attack vector and payload, not the target constraints, so they do not address the need to protect the executive leadership team.
Go deeper
Related to this question
Learn chapter
NTLM Relay Attacks and Responder
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.