hardMultiple Choice
PT0-002 A 'no-fail' clause prohibits service outages Practice Question
A 'no-fail' clause prohibits service outages. How should the tester address high-risk tests like SQL injection?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require a staging environment for testing
Testing in a staging environment prevents real outages. Option A is wrong because it removes important tests. Option C is wrong because it does not prevent outages. Option D is wrong because it is irresponsible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove all high-risk tests from the scope
Why it's wrong here
Removing all high-risk tests from scope eliminates the very techniques that would reveal critical exploitable vulnerabilities, such as privilege escalation, lateral movement, or Denial-of-Service. Although this reduces the chance of an outage, it also reduces the test's ability to validate real-world security defenses, leaving the organization with a false sense of security. A no-fail clause does not justify blind spots in coverage; instead, the tester should adapt testing methodologies to operate safely while still probing high-risk areas in a controlled manner.
- ✓
Require a staging environment for testing
Why this is correct
Requiring a staging environment is the only option that truly eliminates production risk while preserving test depth. A well-configured staging environment, ideally deployed with the same versions, patches, and security controls as production, allows the tester to execute even destructive or high-impact exploits without violating the no-fail clause. This approach maintains test validity because the attacker's interaction with the system is functionally identical, assuming network segmentation and data fidelity are properly addressed. The key is to validate the staging environment's parity before testing.
- ✗
Include a clause that the tester is not liable
Why it's wrong here
An indemnity clause or liability waiver only addresses financial and legal consequences after a service outage occurs; it does nothing to prevent the outage in the first place, which is what the no-fail clause demands. Such a legal provision may actually increase risk by reducing the tester's accountability, potentially leading to less careful handling of exploit attempts. This is a contractual mitigation, not a technical safeguard, and cannot substitute for proper environment targeting or controlled testing procedures.
- ✗
Proceed with testing and hope no outages occur
Why it's wrong here
Proceeding with no safeguards while hoping for zero downtime is a gamble that directly contradicts a no-fail clause, since any outage is an immediate violation regardless of the tester's intentions. This approach lacks any contingency planning, rollback strategy, or operational oversight, and it is widely considered an unprofessional execution of a security engagement. Real-world consequence: a single failed exploit could cascade into a production service outage, causing business damage and legal exposure that a simple hope cannot mitigate.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.