Courseiva
Engagement Management →hardMultiple Choice

PT0-002 Engagement Management Practice Question

A penetration tester is conducting a grey box test on a web application. During the test, the tester discovers that the application is hosted on a cloud infrastructure that belongs to a third-party provider. The client did not mention this provider in the scope. What is the best course of action regarding testing this infrastructure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Stop testing the cloud infrastructure and notify the client

Testing third-party infrastructure without permission is illegal and violates the rules of engagement. The tester should stop testing that part and inform the client.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the cloud provider to the scope without notifying the client

    Why it's wrong here

    Adding the cloud provider to scope unilaterally circumvents the client-approved engagement boundaries; a pen test's scope is a contractual agreement between the tester and the client, and expanding it to include a third party's infrastructure requires the client's explicit sign-off and typically a separate authorization document from the provider. Unilaterally modifying scope exposes you to breach-of-contract liability and could invalidate your legal protections, so any scope change must be routed through the client and documented in writing.

  • ✓

    Stop testing the cloud infrastructure and notify the client

    Why this is correct

    The correct action is to immediately halt all testing against the cloud-infrastructure components that fall outside the client-authorized scope. Because the infrastructure is owned and operated by the cloud provider as a third party, continuing against it without authorization could constitute unauthorized access under laws like the CFAA or the Computer Misuse Act, and the tester must notify the client so the client can formally amend the scope or obtain written permission from the provider.

  • ✗

    Continue testing because the application is owned by the client

    Why it's wrong here

    The fact that the application itself is owned by the client does not grant permission to test the cloud provider's underlying infrastructure. In a typical IaaS/PaaS engagement, the provider retains responsibility for the host, network, and virtualization layers, and testing those layers without the provider's explicit, written authorization is outside the engagement and potentially illegal—even if the application lives in that environment.

  • ✗

    Obtain verbal permission from the cloud provider and proceed

    Why it's wrong here

    Verbal permission from the cloud provider is not legally enforceable and fails to meet the standard of documented authorization required for penetration testing. A proper authorization must be a written agreement (often a Pen Test Authorization Addendum) issued by the provider's security or legal team, and it must also be incorporated into the client's scope change—otherwise, the tester remains exposed to civil and criminal liability while probing the provider's infrastructure.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.