hardMultiple Choice
PT0-002 Practice Question: A medium-sized e-commerce company, CyberMart, has…
A medium-sized e-commerce company, CyberMart, has contracted your penetration testing firm to assess their security posture. The company operates from three physical locations: headquarters, a data center, and a remote warehouse. They have a flat internal network but separate VLANs for production, development, and guest Wi-Fi. CyberMart's CISO insists that the test must be conducted without causing any disruption to the production environment, especially the payment processing system. The test should simulate an external attacker targeting the public-facing web servers and an internal attacker who has gained initial access to the guest network. The CISO also requests that all testing be done during off-peak hours to minimize impact. You are preparing the rules of engagement. Which of the following is the most appropriate action to include in the ROE to satisfy the client's requirements while maintaining a realistic test scenario?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow testing on all VLANs except the production VLAN containing payment processing, with a rule to immediately stop if any degradation is observed.
Option B is correct because it satisfies the CISO's requirement of avoiding disruption to the production payment system by explicitly excluding the production VLAN from testing, while still allowing realistic external and internal (guest network) attack simulation and adding a stop condition if degradation occurs. This balances test coverage with the no-disruption constraint during off-peak hours. Option A is wrong because permitting denial-of-service tests, even off-peak, risks disrupting production and violates the no-disruption requirement. Option C is wrong because excluding all internal testing fails to simulate the internal attacker on the guest network. Option D is wrong because restricting testing to only the guest network and external IPs unnecessarily excludes other non-production VLANs such as development, reducing test scope without a stated need.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include all VLANs but with explicit permission to conduct denial-of-service tests only during off-peak hours.
Why it's wrong here
Authorizing denial-of-service tests on all VLANs, even during off-peak hours, still risks production outages and cascading failures that could affect payment processing. The CISO explicitly requested avoiding degradation, not merely scheduling it for low-traffic windows, and off-hours operations often have fewer staff available to respond to incidents. Furthermore, including the production payment VLAN violates the requirement to protect that critical segment. A proper rules of engagement should exclude critical systems entirely and require a kill switch, not just time-based restrictions.
- ✓
Allow testing on all VLANs except the production VLAN containing payment processing, with a rule to immediately stop if any degradation is observed.
Why this is correct
This scope correctly balances comprehensive internal testing with business continuity: it includes all network segments to simulate both external and internal attackers, but excludes the payment processing VLAN to protect cardholder data and PCI DSS-scoped systems. The immediate-stop rule serves as a safety kill switch, ensuring any sign of degradation halts testing before impact. This covers internal segmentation testing across VLANs, which is essential for a medium e-commerce company, while respecting the CISO's risk tolerance.
- ✗
Focus exclusively on the external web servers and exclude internal network testing due to the risk of disruption.
Why it's wrong here
Excluding internal network testing entirely prevents the assessment from validating the internal attacker scenario, which is specifically part of the test objectives. External web server testing alone cannot discover issues like VLAN hopping, weak internal lateral movement controls, or excessive trust relationships between internal systems. The CISO's concern about disruption does not justify omitting an entire attack surface; instead, controlled testing with safeguards should be used to mitigate risk.
- ✗
Restrict testing to only the guest network and external IPs, excluding all production VLANs.
Why it's wrong here
Limiting testing to the guest network and external IPs ignores the production VLANs where the most sensitive data and critical business processes reside. This fails to validate internal segmentation between guest and corporate networks, as well as between different production tiers, leaving the actual internal attacker path untested. While it minimizes disruption, it also makes the penetration test largely irrelevant to the company's risk profile, as the guest network is typically already isolated and external testing is only one small component.
Visual reference
Go deeper
Related to this question
Learn chapter
Remote Code Execution (RCE) Vulnerabilities
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.