easyMultiple Choice
PT0-002 Practice Question: A client wants a social engineering test focusing…
A client wants a social engineering test focusing on phishing. What should be included in the scope to ensure ethical handling?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rules of engagement for notifying employees after the test
The rules of engagement for notifying employees after the test, because a phishing social engineering engagement must define how and when targets are debriefed or notified to avoid causing undue harm, panic, or operational disruption, and to keep the test ethical and authorized. Rules of engagement also establish authorization boundaries, escalation contacts, and handling of any real credentials or sensitive data captured during the phishing simulation. Option B is not appropriate for the scope document because exposing attacker infrastructure details is an operational detail, not an ethical safeguard. Option C, approved sender domains, is a technical setup item rather than the ethical handling requirement. Option D, the expected number of employees who fall for the email, is a success metric, not a control for ethical conduct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The rules of engagement for notifying employees after the test
Why this is correct
Rules of engagement define the authorised scope, timing, and post-test notification process, satisfying the ethical-handling requirement. Specifying how and when employees are informed prevents real-world harm, protects the client's staff, and keeps the phishing simulation within agreed legal and contractual boundaries.
- ✗
The attacker infrastructure details
Why it's wrong here
Publishing attacker infrastructure details exposes the testing servers to the client's defenders, who could block or trace them mid-campaign, invalidating results. Such details belong in the rules of engagement as a controlled notification channel. They are tempting because infrastructure must be documented for authorisation, but scope should instead define target boundaries and permitted techniques.
- ✗
The list of approved sender domains to use
Why it's wrong here
Approved sender domains govern email authenticity and delivery, not ethical handling of targets or captured data. Scope needs target ranges, exclusions and rules for handling harvested credentials. Sender domains are tempting because they prevent spoofing complaints and are essential for the technical setup, but they do not address ethics.
- ✗
The expected number of employees who should fall for the email
Why it's wrong here
A predicted fall rate is a success metric, not a scope control; it neither limits which employees may be targeted nor constrains handling of captured credentials. Scope must define target lists, exclusions and data-handling rules. Expected click rates are tempting because they frame the engagement's objectives, but they belong in the report's success criteria.
Go deeper
Related to this question
Learn chapter
Phishing Campaigns in Penetration Testing
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.