hardMultiple Choice
PT0-002 Practice Question: A client wants a penetration test that includes…
A client wants a penetration test that includes testing of their internal network, external perimeter, and wireless. However, they have a very limited budget. Which approach would best meet the client's needs while staying within budget?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a targeted test focusing on high-risk areas identified through threat modeling
Conducting a targeted test focused on high-risk areas identified through threat modeling allows coverage of all three areas with limited depth, maximizing value within budget. Skipping areas or using only automated tools may not meet the client's full requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use vulnerability scanners for all three areas
Why it's wrong here
Vulnerability scanners are point-in-time, signature-based tools that enumerate known CVEs and configuration weaknesses, but they cannot validate business logic flaws, chain exploits, or assess the actual security impact of a finding. Relying solely on scanners for all three areas (internal, external, wireless) would produce a high volume of false positives and miss manual test techniques such as credential stuffing, privilege escalation, and post-exploitation pivoting. Furthermore, wireless testing requires site surveys and protocol-level analysis (e.g., WPA3 downgrade attacks, rogue AP detection) that automated scanners typically do not perform with sufficient depth. This approach fails to meet the client's expectation of an active, adversarial penetration test rather than a compliance-focused vulnerability assessment.
- ✓
Conduct a targeted test focusing on high-risk areas identified through threat modeling
Why this is correct
A targeted test driven by threat modeling is the correct balance because it aligns the scope with the client's actual risk profile, focusing time and budget on the assets and attack paths that matter most. Threat modeling (e.g., STRIDE, DREAD, or attack trees) identifies high-value targets such as internet-facing applications, sensitive data stores, and internal systems reachable via phishing or lateral movement. By prioritizing these areas, the tester can apply manual exploitation techniques and deeper verification on the highest-risk components while still covering all three requested domains (internal, external, wireless) in a scoped manner. This approach is more effective than blind scanning or omitting a requested area, as it delivers actionable findings tied to business impact rather than a generic checklist.
- ✗
Only test internal and external
Why it's wrong here
Omitting wireless testing is a direct scope violation because the client explicitly requested testing of all three areas; a penetration test that skips wireless leaves rogue access points, weak WPA2-PSK passphrases, and client-side attacks (e.g., Evil Twin, Karma attacks) unassessed. Internal and external testing alone may identify network vulnerabilities, but wireless often serves as an alternate entry point that bypasses perimeter controls, allowing an attacker to gain a foothold without touching the wired network. From a contractual standpoint, failing to test a requested component could expose the tester to liability and the client to an incomplete risk assessment. A proper test must include wireless reconnaissance and exploitation to meet the stated scope and provide comprehensive coverage.
- ✗
Only test external and wireless
Why it's wrong here
Testing only external and wireless ignores the internal network, which is a critical gap because most successful attacks originate from inside the perimeter — whether through a compromised endpoint, a malicious insider, or phishing that leads to lateral movement. Internal testing validates segmentation, host hardening, patch management, and Active Directory attack paths (e.g., Kerberoasting, pass-the-hash, ACL abuse), which cannot be assessed from an external perspective. Omitting internal testing means the client will have no actionable data on how far an attacker can pivot after breaching the perimeter, leaving high-impact risks like domain compromise undetected. A complete penetration test must include an internal assessment to uncover these post-exploitation threats and validate the effectiveness of insider-threat defenses.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.