hardMultiple Choice
PT0-002 Practice Question: A contract prohibits DoS testing, but a tester…
A contract prohibits DoS testing, but a tester finds a WAF that could be tested with a technique resembling slowloris. What is the best course of action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request a scope change to include DoS testing
The correct option is D: Request a scope change to include DoS testing. Slowloris is a denial-of-service technique that holds many partial HTTP connections open to exhaust the web server's connection pool, so testing it would violate the contract's explicit prohibition on DoS testing; the tester must obtain written authorization via a scope change before performing it. Option A is wrong because a buffer overflow is also an intrusive availability/exploitation test outside the authorized scope. Option B is wrong because proceeding with slowloris directly breaches the contract. Option C is wrong because even a single malformed HTTP request is unauthorized testing against a WAF that was not in scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a different technique, such as a buffer overflow
Why it's wrong here
A buffer overflow is also an availability and integrity attack that can crash the target, so it remains outside the authorised scope just as DoS does. It tempts as an alternative WAF probe, yet it would be valid only where the contract explicitly authorises exploitation attempts.
- ✗
Proceed with a slowloris attack
Why it's wrong here
Slowloris exhausts connections to deny service, which the contract explicitly prohibits, so proceeding breaches the engagement's scope and authorisation. It tempts because the WAF looks vulnerable, but such testing is only lawful when the rules of engagement permit denial-of-service.
- ✗
Send a single malformed HTTP request and observe
Why it's wrong here
A single malformed request cannot validate slowloris-style connection exhaustion, so it fails to test the WAF behaviour the tester identified. It tempts as a low-impact probe, but malformed-request fuzzing belongs in authorised input-validation testing, not availability assessment.
- ✓
Request a scope change to include DoS testing
Why this is correct
The contract explicitly prohibits DoS testing, so performing a slowloris-style attack would breach the agreed scope. Requesting a scope change obtains written authorisation before any testing, keeping the engagement legal and within the rules of engagement.
Go deeper
Related to this question
Learn chapter
Impacket Suite for Windows Exploitation
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Buffer overflow
A buffer overflow is a type of software vulnerability where a program writes more data to a memory buffer than it was designed to hold, causing adjacent memory to be overwritten.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.