PT0-002 Engagement Management Practice Question
A company is planning a social engineering engagement. Which TWO items should be included in the pre-engagement documentation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Emergency contact list
Pre-engagement documentation should include the rules of engagement (RoE) and emergency contacts to handle incidents during social engineering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
List of all employee passwords
Why it's wrong here
Providing real employee credentials to testers defeats the purpose of a social engineering assessment, since the entire exercise is to see whether users can be manipulated into revealing secrets or granting access themselves. Distributing passwords beforehand also broadens the attack surface and creates a liability if those artifacts leak. The only credential data a social engineer might ask for is a validation list of corporate username formats, not the passwords.
- ✗
Network topology diagrams
Why it's wrong here
Network topology diagrams describe routers, switching layers, and subnet design, which are crucial for network penetration testing but tell a social engineer almost nothing about how employees behave under phishing or phone pretexting. Sharing these diagrams alongside a people-focused engagement could even create confusion about whether the tester is allowed to perform technical exploitation, muddying the scope. For a pure social engineering test, such artifacts are neither helpful nor required.
- ✗
Source code of all applications
Why it's wrong here
Application source code is relevant to code review and vulnerability research, yet it has no bearing on persuading a receptionist or finance clerk to perform a requested action. A social engineer operates through communication channels, not by inspecting code paths, and providing source code would expose the organization to additional risk without improving the engagement's fidelity. It is a classic example of bringing the wrong technical asset to a human-focused assessment.
- ✓
Emergency contact list
Why this is correct
An emergency contact list is a mandatory deliverable for social engineering engagements because any deployed scenario could accidentally trigger a real security incident or expose a worker to harm. The lead tester needs named individuals with the authority to approve an immediate abort, making this list as operationally important as the RoE itself. Without these contacts, a seemingly harmless test could spiral out of control with no rapid way to stop it.
- ✓
Rules of engagement
Why this is correct
Rules of engagement define the precise activities the social engineer may perform, the targets and exclusions, and the signals or conditions that require an immediate stop. They transform an inherently deceptive exercise into a controlled legal test by setting boundaries such as no physical entry, no impersonation of law enforcement, or time-of-day restrictions. The RoE is the document that makes the entire engagement consensual and defensible, and it must be signed before testing begins.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.