easyMultiple Choice
PT0-002 Practice Question: A penetration tester is conducting an external…
A penetration tester is conducting an external network assessment for a client. During the reconnaissance phase, the tester identifies an IP address range that is not listed in the rules of engagement (ROE). The client had initially provided a list of authorized target IPs. What should the tester do next?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stop testing and notify the client to update the ROE.
Testing outside the defined scope is unauthorized and could breach contract or legal boundaries. The correct course is to pause and seek clarification, updating the ROE before proceeding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Stop testing and notify the client to update the ROE.
Why this is correct
When an external assessment reveals IP addresses that are not listed in the Rules of Engagement (ROE), the only compliant action is to halt all testing and immediately notify the client. Continuing against those IPs—even if they belong to the client—would exceed the written authorization, potentially constituting unauthorized access under statutes like the Computer Fraud and Abuse Act (CFAA) and breaching the contract. The client must formally update the ROE to add the new addresses, after verifying ownership and confirming the testing window, before any activity against those targets can legally begin.
- ✗
Include the new IPs in the test scope and proceed.
Why it's wrong here
Unilaterally folding the newly discovered IPs into the test scope and proceeding violates the explicit boundaries of the ROE, regardless of the tester's belief that the assets are owned by the client. This action could invalidate the entire engagement, expose the tester to civil liability, and trigger an incident response from the client's security team, which may mistake the activity for an attack. Additionally, the client may not have authority to authorize testing on those IPs if they are hosted with a third party or shared infrastructure, so any testing without written amended authorization is both professionally and legally indefensible.
- ✗
Perform a quick scan of the new IPs to gather more information.
Why it's wrong here
Performing even a 'quick scan' of the new IPs constitutes active reconnaissance and is a form of testing that is outside the ROE; there is no de minimis threshold for unauthorized scanning in an engagement. Such activity can be detected by intrusion detection/prevention systems (IDS/IPS) and might be reported to law enforcement as an attempted intrusion, especially because the tester has no written authorization for those targets. Even if the intent is merely to gather information for a future scope discussion, that activity itself is an unauthorized interaction with the systems and must be deferred until the ROE is formally amended.
- ✗
Ignore the new IPs and only test the provided range.
Why it's wrong here
While simply ignoring the new IPs technically keeps the tester within the confines of the ROE, it is an incomplete and passive approach that fails the core objective of the assessment, which is to identify vulnerabilities across the client's actual attack surface. The discovery of those IPs is itself a finding—it indicates that the client's external footprint is larger than documented, and a professional tester must communicate that observation so the client can decide whether to expand the scope. By staying silent, the tester withholds material information that could leave critical exposed assets unassessed and unmitigated, violating the spirit of the engagement even if not the letter of the ROE.
Go deeper
Related to this question
Learn chapter
Physical Security Testing Techniques
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.