PT0-002 Engagement Management Practice Question
A penetration tester is planning a social engineering engagement targeting employees of a client. The client requests that only non-managerial staff be tested. Which scoping consideration is most directly affected by this request?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Personnel scope
Personnel scope determines which individuals or groups are targeted in social engineering tests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IP address range
Why it's wrong here
An IP address range defines the network hosts and subnets eligible for infrastructure scanning or exploitation, but social engineering manipulates human users rather than network services. Since the target is people—employees with specific roles and access—an IP scope provides no information about which individuals, departments, or identities may be approached. Consequently, specifying an IP range would be a technical network-scoping step that does not support planning a phishing or vishing campaign.
- ✗
Production vs. staging
Why it's wrong here
Production versus staging distinguishes live, user-facing systems from isolated test environments, a distinction that applies to software deployment and change management—not to personnel targeting. Social engineering engagements are concerned with the people who operate or use those systems, and whether a server is in production or staging rarely affects whether an employee can be tricked into revealing credentials. Therefore, this environmental classification is a red herring when defining the human scope of an engagement.
- ✗
Third-party services
Why it's wrong here
Third-party services refer to external vendors or cloud providers whose infrastructure or offerings may be used by the target organization, but such entities are separate legal and operational units. A social engineering engagement against the organization targets its own employees, partners, or contractors, not the external provider's staff unless supply-chain pretexting is explicitly authorized. So listing third-party services as part of the engagement scope would incorrectly broaden the target set beyond the client's personnel.
- ✓
Personnel scope
Why this is correct
Personnel scope explicitly enumerates which individuals or employee groups—such as executives, IT administrators, or finance staff—are authorized targets for social engineering. It also dictates permissible attack vectors like email phishing, phone vishing, or physical tailgating, while ensuring the engagement remains within agreed ethical and legal boundaries. Without a defined personnel scope, testing could inadvertently target non-consenting individuals, violating rules of engagement and creating legal liability.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.