Courseiva
Engagement Management →mediumMultiple Choice

PT0-002 Engagement Management Practice Question

A company wants to simulate a real-world attack scenario where the penetration tester has no prior knowledge of the environment and must act as an external threat actor. However, the tester is allowed to use social engineering to gain initial access. Which type of engagement is most appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Red team exercise

A red team exercise is a full-scope adversary simulation that can include social engineering and black box testing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Red team exercise

    Why this is correct

    A red team exercise is a full-scope, objective-based simulation that mimics a real adversary's tactics, techniques, and procedures (TTPs), including social engineering, physical access, email phishing, and exploitation. Unlike a single-vector assessment, it is designed to test the organization's overall security posture — people, processes, and technology — by stealthily moving toward a defined goal, such as data exfiltration or domain compromise. Social engineering is a core component because it validates whether employee awareness and security policies can resist real-world manipulation.

  • ✗

    Network penetration test

    Why it's wrong here

    A network penetration test is a technical assessment of network infrastructure, targeting issues like misconfigured firewalls, unpatched servers, weak protocol settings, and improper network segmentation. Its scope and rules of engagement typically limit activities to specified IP ranges and system layers, and it usually does not involve attempting to trick employees through social engineering. While the test can reveal exploitable network vulnerabilities, it does not simulate a realistic, multidimensional attack that combines human interaction and social manipulation.

  • ✗

    Wireless penetration test

    Why it's wrong here

    A wireless penetration test is narrowly scoped to the radio-frequency environment, evaluating WPA2/WPA3 weaknesses, rogue access points, evil twin deployments, deauthentication attacks, and client misassociation. This assessment does not include social engineering, physical entry, or other organizational attack surfaces, so its results are limited to the wireless domain. It can support a red team operation but is not equivalent to a real-world scenario involving phishing or human deception.

  • ✗

    Web application penetration test

    Why it's wrong here

    A web application penetration test focuses exclusively on application-layer flaws such as SQL injection, cross-site scripting, broken authentication, and access control failures, typically aligned with the OWASP Top 10. Because the test is scoped to the web application's code, configuration, and business logic, it does not evaluate human susceptibility to phishing or the physical security of a facility. Thus, it cannot represent a real-world attack that uses social engineering as a primary entry vector.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.