Question 521 of 185
hardMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A client has a critical web application that…
A client has a critical web application that cannot be tested in the production environment due to availability requirements. A staging environment exists that exactly mirrors production, but it uses different IP addresses, domain names, and a subset of data. The staging environment is isolated from production networks. Which scoping element is most important to include in the rules of engagement to ensure a valid test?
⚠ Common exam trap
Watch out — candidates often confuse operational constraints (like non-disruptive techniques) with scoping requirements, or they may incorrectly assume that including production IPs as a 'safety net' is acceptable, when it actually violates the core principle of scope definition and availability requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Explicitly define the staging environment as the target scope
The staging environment is an exact mirror of production but uses different IP addresses, domain names, and a subset of data. Explicitly defining the staging environment as the target scope ensures the tester focuses all activities on the authorized systems, preventing any accidental impact on production. This scoping element is critical for a valid test because it aligns the test with the client's availability requirements while still allowing comprehensive security testing on a representative environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Explicitly define the staging environment as the target scope
Why this is correct
The rules of engagement (RoE) must enumerate the exact authorized targets before any testing activity occurs. Explicitly listing the staging environment's IP ranges, hostnames, or domains legally authorizes the tester to interact only with those systems and prevents any claim of unauthorized activity. Without this explicit designation, even a benign scan of staging could be interpreted as an attack on production, and the tester would have no valid contract for findings. This is the foundational element that makes the engagement legal and executed within agreed boundaries.
- ✗
Require the tester to use non-disruptive testing techniques only
Why it's wrong here
Requiring non-disruptive techniques, such as passive reconnaissance or read-only queries, reduces the chance of causing outages but does nothing to establish which systems are legally in scope. If the staging environment is not listed in the rules of engagement, then using only non-disruptive techniques against any target still violates authorization because the target itself was never permitted. The how of testing is a separate constraint; the where, the specific authorized target, must be resolved first. Additionally, even 'non-disruptive' requests to a production system can generate production alerts, log noise, regulatory exposure, and performance degradation under load, so it cannot substitute for target definition.
- ✗
Include the production IP ranges in the scope 'just in case'
Why it's wrong here
Adding production IP ranges to the scope 'just in case' expands the authorized attack surface to systems the organization explicitly needs protected at all costs. It creates a material risk of accidental testing against production, which can violate availability, integrity, and confidentiality demands—especially if a tester's tool scans a range and hits a production server. It also enlarges the legal exposure of both client and tester, because any action on production beyond what is necessary to ensure availability is unauthorized and potentially harmful. Scope should be defined with precision and minimalism; production should be explicitly listed as out-of-scope, not included as a hedge.
- ✗
Specify that the test must be performed from the internet only
Why it's wrong here
Mandating that the test originate from the internet defines the source of testing, which is a valid rule-of-engagement clause but does not specify the target environment. It is entirely possible to test a staging environment from the internet if staging is exposed or reachable through a controlled path, but if staging is on an internal network, this restriction would make the test impossible. More importantly, the failure to explicitly name the staging environment as the target remains unresolved; source location is orthogonal to target authorization. Without a defined target, performing the test from the internet would still be an unauthorized action because no environment has been legally designated as the target.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.