Courseiva
easyMultiple Choice

PT0-002 Practice Question: A client wants a social engineering test focusing…

A client wants a social engineering test focusing on phishing. What should be included in the scope to ensure ethical handling?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The rules of engagement for notifying employees after the test

The rules of engagement for notifying employees after the test, because a phishing social engineering engagement must define how and when targets are debriefed or notified to avoid causing undue harm, panic, or operational disruption, and to keep the test ethical and authorized. Rules of engagement also establish authorization boundaries, escalation contacts, and handling of any real credentials or sensitive data captured during the phishing simulation. Option B is not appropriate for the scope document because exposing attacker infrastructure details is an operational detail, not an ethical safeguard. Option C, approved sender domains, is a technical setup item rather than the ethical handling requirement. Option D, the expected number of employees who fall for the email, is a success metric, not a control for ethical conduct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The rules of engagement for notifying employees after the test

    Why this is correct

    Rules of engagement define the authorised scope, timing, and post-test notification process, satisfying the ethical-handling requirement. Specifying how and when employees are informed prevents real-world harm, protects the client's staff, and keeps the phishing simulation within agreed legal and contractual boundaries.

  • ✗

    The attacker infrastructure details

    Why it's wrong here

    Publishing attacker infrastructure details exposes the testing servers to the client's defenders, who could block or trace them mid-campaign, invalidating results. Such details belong in the rules of engagement as a controlled notification channel. They are tempting because infrastructure must be documented for authorisation, but scope should instead define target boundaries and permitted techniques.

  • ✗

    The list of approved sender domains to use

    Why it's wrong here

    Approved sender domains govern email authenticity and delivery, not ethical handling of targets or captured data. Scope needs target ranges, exclusions and rules for handling harvested credentials. Sender domains are tempting because they prevent spoofing complaints and are essential for the technical setup, but they do not address ethics.

  • ✗

    The expected number of employees who should fall for the email

    Why it's wrong here

    A predicted fall rate is a success metric, not a scope control; it neither limits which employees may be targeted nor constrains handling of captured credentials. Scope must define target lists, exclusions and data-handling rules. Expected click rates are tempting because they frame the engagement's objectives, but they belong in the report's success criteria.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.