hardMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration test is being conducted for a…
A penetration test is being conducted for a healthcare organization subject to HIPAA. The tester is given access to a production system that contains electronic protected health information (ePHI). Which of the following should be included in the rules of engagement to ensure compliance?
⚠ Common exam trap
Candidates often confuse a BAA (a separate legal requirement) with a clause that must be included in the rules of engagement, or they assume encryption is a mandatory RoE clause when HIPAA treats it as addressable and not a procedural scope item.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A detailed data handling and destruction procedure within the rules of engagement.
HIPAA requires covered entities to ensure the confidentiality, integrity, and availability of ePHI, which includes proper disposal of data after testing. A detailed data handling and destruction procedure within the rules of engagement (RoE) ensures that test data containing ePHI is securely wiped or destroyed in compliance with 45 CFR § 164.310(d)(2)(i) and NIST SP 800-88 guidelines. Without this clause, the tester might leave residual ePHI on production systems, violating HIPAA's security rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A clause requiring encryption of all test data at rest and in transit.
Why it's wrong here
Encryption in transit/at rest is a security control required by HIPAA, but merely requiring encryption doesn't specify key management, access controls, data minimization, retention periods, or secure destruction methods. RoE must include full data lifecycle procedures, including what data is collected, who can access it, how it's logged, and how it's purged after testing. Encryption alone leaves gaps like unencrypted copies in memory or logs, and doesn't cover physical destruction of media.
- ✗
A business associate agreement (BAA) signed between the client and the testing firm.
Why it's wrong here
A BAA is a legal contract under HIPAA that outlines permitted uses and disclosures of PHI, but it doesn't define the specific operational boundaries, environments, tools, or handling procedures for the penetration test. The RoE is the technical and operational document that governs execution, such as scope, timing, and data handling. A BAA also would not address, for example, how testers should handle ePHI on compromised systems or the exact destruction process, making it insufficient as the primary safeguard.
- ✓
A detailed data handling and destruction procedure within the rules of engagement.
Why this is correct
Given the healthcare context and HIPAA's Security Rule, the RoE must specify controls for the entire lifecycle of ePHI encountered during the test—including collection limits, encryption, access restrictions, storage locations, and a verifiable destruction method such as cryptographic wipe or physical shredding after assessment. This is the only option that directly addresses the unique regulatory requirement for protecting ePHI and ensuring no residual sensitive data remains. A detailed procedure ensures testers know exactly what to do if they encounter live PHI, including logging, minimizing exposure, and confirming removal.
- ✗
A restriction to only test in non-production environments.
Why it's wrong here
Restricting testing to non-production environments is a risk mitigation tactic, but it may be infeasible because production systems often contain the actual ePHI and vulnerabilities only present in the live environment; additionally, the RoE must still govern data handling in any environment, including test copies that may contain PHI. This option is too narrow and doesn't replace the need for comprehensive data handling and destruction procedures. A client might also require production testing to validate security controls, so the RoE must address ePHI protection in both production and non-production contexts.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.