PT0-002 Engagement Management Practice Question
A penetration tester is planning a test that involves scanning for vulnerabilities across a large IP range. The client has provided a list of IPs that are in-scope, but the tester notices that some IPs belong to a third-party company hosting a client application. What should the tester do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exclude the third-party IPs and notify the client
The tester must ensure that all in-scope IPs are authorized. If an IP belongs to a third party, the tester needs written permission from that provider before testing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assume the client has permission and scan all IPs
Why it's wrong here
Assuming the client has permission to authorize scans of every IP in a target range is a dangerous unsafe assumption. In penetration testing, authorization is strictly limited to assets owned or explicitly approved for testing by the client; third-party IPs, such as cloud-hosted services or partner infrastructure, require separate permission from the entity that controls them. Scanning IPs without that authorization can violate laws like the Computer Fraud and Abuse Act (CFAA) or equivalent statutes, potentially exposing both the tester and the client to legal liability. You must verify scope in the rules of engagement and never rely on assumptions when adding assets to the scope.
- ✓
Exclude the third-party IPs and notify the client
Why this is correct
The correct action is to exclude the third-party IPs from active scanning and promptly notify the client that these assets are outside the authorized scope. This respects the legal boundaries of the engagement and ensures that the client takes responsibility for obtaining permission from the third-party owner if the assets need to be tested. The penetration tester should document the exclusion and request explicit written authorization or a revised scope before performing any scanning activity against those IPs. This approach aligns with contractual requirements, legal compliance, and professional standards in penetration testing.
- ✗
Scan the IPs because they are on the client's list
Why it's wrong here
Simply having the IPs included in the client's provided list does not automatically grant authorization to scan them, especially when those addresses are owned by a third party. The client may not be aware that certain IPs fall outside their control, or they may have acquired a list of IPs without verifying ownership. Performing the scan based on the list alone transfers legal responsibility to the tester, who is still liable for unauthorized access. The tester must verify ownership, identify third-party assets, and confirm explicit written authorization beyond a simple list entry before conducting the scan.
- ✗
Scan only the third-party IPs that respond to ping
Why it's wrong here
Scanning only the third-party IPs that respond to ping does not avoid the core legal problem, because responding to an ICMP echo request is not the same as granting permission to scan. Even if a host answers ping, active service discovery and vulnerability scanning against that host constitute unauthorized network activity under the third party's exclusive control. Additionally, limiting the scan to responsive hosts is not a valid scoping method; it omits potentially critical assets while still violating third-party rights. The only acceptable action is to exclude these IPs entirely or obtain explicit third-party authorization before any scanning occurs.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.