Courseiva
mediumMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A client with a hybrid infrastructure…

A client with a hybrid infrastructure (on-premises and cloud IaaS) requests a penetration test covering both environments. The cloud provider's terms of service require notification and restrict scanning to specific IP ranges. In which document should these constraints be documented?

⚠ Common exam trap

The PT0-002 exam often tests the distinction between the SOW (high-level scope) and the ROE (detailed operational rules), so the trap here is that candidates confuse the SOW's 'what' with the ROE's 'how' and 'under what constraints'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Rules of Engagement (ROE)

The Rules of Engagement (ROE) document is the authoritative source for defining the legal and technical boundaries of a penetration test, including provider-mandated constraints such as notification requirements and restricted IP ranges. In a hybrid infrastructure with cloud IaaS, the ROE must explicitly list the allowed source IPs, target CIDR blocks, and any time windows or rate limits imposed by the cloud provider to ensure compliance with their terms of service. This document is signed by both the client and the testing team before any testing begins, making it the correct place to document these operational constraints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Non-Disclosure Agreement (NDA)

    Why it's wrong here

    An NDA is a legal contract that protects the confidentiality of information shared during the engagement, but it does not define operational boundaries such as allowed IP ranges, notification procedures, or testing windows. It prevents the disclosure of findings and sensitive data but says nothing about technical constraints or scope limitations, making it unsuitable for specifying how the penetration test should be executed.

  • Rules of Engagement (ROE)

    Why this is correct

    The Rules of Engagement (ROE) is the authoritative document that defines the terms under which the penetration test is conducted, including explicit authorization for specific IP ranges, allowable testing times, emergency contacts, notification requirements for detected incidents, and any prohibited techniques such as social engineering or denial-of-service. It operationalizes the client's objectives into concrete constraints that testers must follow to stay within legal and ethical boundaries. For a hybrid infrastructure spanning on-premises and cloud IaaS, the ROE also clarifies cloud-specific considerations like consent for third-party testing and data handling.

  • Penetration Testing Report

    Why it's wrong here

    A penetration testing report is a post-engagement deliverable that documents vulnerabilities found, exploitation steps, and remediation recommendations; it is created after testing is complete and has no role in defining pre-test constraints. It may include an executive summary and technical details, but it cannot authorize or restrict tester actions because it does not exist at the time when rules must be established. Therefore, it is not the right document for specifying notification or IP range requirements.

  • Scope of Work (SOW)

    Why it's wrong here

    A Statement of Work (SOW) typically outlines high-level objectives, deliverables, timeline, and responsibilities at a project management level, but it lacks the granular technical details needed for execution, such as specific IP scope, testing windows, and approved methodologies. The SOW establishes what will be done and at a high level, but the detailed constraints—like which systems are in-scope and how to handle critical findings—are conventionally deferred to the ROE to avoid cluttering the contractual agreement. Thus, while related, the SOW alone does not specify the detailed operational boundaries.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.