Courseiva
Engagement Management →mediumMultiple Choice

PT0-002 Engagement Management Practice Question

A penetration tester is about to start an engagement. Which document outlines the IP ranges that are in scope, the testing window, and the emergency stop criteria?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rules of Engagement (RoE)

The rules of engagement (RoE) specify technical and procedural boundaries for the test.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Non-Disclosure Agreement (NDA)

    Why it's wrong here

    The NDA is a legal confidentiality contract that governs how the tester handles the client's sensitive information, such as findings, credentials, and business data. It does not define authorized IP addresses, testing windows, or prohibited test techniques, so it cannot serve as the technical scope document. While an NDA is essential for protecting data, it is entirely separate from the operational constraints that tell the tester what to scan, when, and how.

  • ✗

    Statement of Work (SOW)

    Why it's wrong here

    The SOW outlines the high-level business terms of the engagement, including deliverables, timelines, milestones, and payment obligations, and may summarize overall objectives. It typically lacks the precise technical constraints needed during testing, such as exact CIDR ranges, specific test windows with time zones, emergency contact procedures, or the authoritative list of prohibited and allowed attack techniques. The SOW establishes what must be delivered, whereas the RoE establishes the technical boundaries and conditions under which the testing may be executed.

  • ✓

    Rules of Engagement (RoE)

    Why this is correct

    The RoE is the authoritative operational document that directly defines the technical constraints and legal boundaries of the penetration test. It includes the exact authorized IP ranges/networks, permitted testing times (including any blackout windows), allowed test types (e.g., active exploitation, social engineering), handling of sensitive data, and specific stop conditions or escalation paths if critical systems fail. Unlike the NDA or SOW, the RoE is the document testers must consult minute-to-minute to ensure every action is authorized and safe.

  • ✗

    Get-out-of-jail letter

    Why it's wrong here

    The get-out-of-jail letter (client authorization letter) is a concise document signed by the client that informs third parties—such as ISPs, cloud providers, or law enforcement—that the tester is performing authorized security activities. Its purpose is to prevent the tester from being accused of unauthorized access, but it does not enumerate technical scope like IP ranges or testing windows, nor does it specify stop conditions or prohibited techniques. It is a liability shield, not a technical playbook, so it cannot replace the detailed operational constraints found in the RoE.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.