PT0-002 Engagement Management Practice Question
A penetration tester is about to start an engagement. Which document outlines the IP ranges that are in scope, the testing window, and the emergency stop criteria?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rules of Engagement (RoE)
The rules of engagement (RoE) specify technical and procedural boundaries for the test.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Non-Disclosure Agreement (NDA)
Why it's wrong here
The NDA is a legal confidentiality contract that governs how the tester handles the client's sensitive information, such as findings, credentials, and business data. It does not define authorized IP addresses, testing windows, or prohibited test techniques, so it cannot serve as the technical scope document. While an NDA is essential for protecting data, it is entirely separate from the operational constraints that tell the tester what to scan, when, and how.
- ✗
Statement of Work (SOW)
Why it's wrong here
The SOW outlines the high-level business terms of the engagement, including deliverables, timelines, milestones, and payment obligations, and may summarize overall objectives. It typically lacks the precise technical constraints needed during testing, such as exact CIDR ranges, specific test windows with time zones, emergency contact procedures, or the authoritative list of prohibited and allowed attack techniques. The SOW establishes what must be delivered, whereas the RoE establishes the technical boundaries and conditions under which the testing may be executed.
- ✓
Rules of Engagement (RoE)
Why this is correct
The RoE is the authoritative operational document that directly defines the technical constraints and legal boundaries of the penetration test. It includes the exact authorized IP ranges/networks, permitted testing times (including any blackout windows), allowed test types (e.g., active exploitation, social engineering), handling of sensitive data, and specific stop conditions or escalation paths if critical systems fail. Unlike the NDA or SOW, the RoE is the document testers must consult minute-to-minute to ensure every action is authorized and safe.
- ✗
Get-out-of-jail letter
Why it's wrong here
The get-out-of-jail letter (client authorization letter) is a concise document signed by the client that informs third parties—such as ISPs, cloud providers, or law enforcement—that the tester is performing authorized security activities. Its purpose is to prevent the tester from being accused of unauthorized access, but it does not enumerate technical scope like IP ranges or testing windows, nor does it specify stop conditions or prohibited techniques. It is a liability shield, not a technical playbook, so it cannot replace the detailed operational constraints found in the RoE.
Go deeper
Related to this question
Learn chapter
Mobile Application Testing
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.