PT0-002 Engagement Management Practice Question
A penetration tester is conducting a grey box test on a web application. During the test, the tester discovers that the application is hosted on a cloud infrastructure that belongs to a third-party provider. The client did not mention this provider in the scope. What is the best course of action regarding testing this infrastructure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stop testing the cloud infrastructure and notify the client
Testing third-party infrastructure without permission is illegal and violates the rules of engagement. The tester should stop testing that part and inform the client.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the cloud provider to the scope without notifying the client
Why it's wrong here
Adding the cloud provider to scope unilaterally circumvents the client-approved engagement boundaries; a pen test's scope is a contractual agreement between the tester and the client, and expanding it to include a third party's infrastructure requires the client's explicit sign-off and typically a separate authorization document from the provider. Unilaterally modifying scope exposes you to breach-of-contract liability and could invalidate your legal protections, so any scope change must be routed through the client and documented in writing.
- ✓
Stop testing the cloud infrastructure and notify the client
Why this is correct
The correct action is to immediately halt all testing against the cloud-infrastructure components that fall outside the client-authorized scope. Because the infrastructure is owned and operated by the cloud provider as a third party, continuing against it without authorization could constitute unauthorized access under laws like the CFAA or the Computer Misuse Act, and the tester must notify the client so the client can formally amend the scope or obtain written permission from the provider.
- ✗
Continue testing because the application is owned by the client
Why it's wrong here
The fact that the application itself is owned by the client does not grant permission to test the cloud provider's underlying infrastructure. In a typical IaaS/PaaS engagement, the provider retains responsibility for the host, network, and virtualization layers, and testing those layers without the provider's explicit, written authorization is outside the engagement and potentially illegal—even if the application lives in that environment.
- ✗
Obtain verbal permission from the cloud provider and proceed
Why it's wrong here
Verbal permission from the cloud provider is not legally enforceable and fails to meet the standard of documented authorization required for penetration testing. A proper authorization must be a written agreement (often a Pen Test Authorization Addendum) issued by the provider's security or legal team, and it must also be incorporated into the client's scope change—otherwise, the tester remains exposed to civil and criminal liability while probing the provider's infrastructure.
Go deeper
Related to this question
Learn chapter
PowerShell for Penetration Testing
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.