Courseiva
mediumMultiple Select

PT0-002 Practice Question: A penetration tester is planning to perform a…

A penetration tester is planning to perform a vulnerability scan of an internal network. Which of the following should be considered before scanning? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse vulnerability scanning with exploitation, assuming that testing exploits (Option E) is part of the scan, when in fact scanning is passive detection and exploitation requires separate authorization and a different phase.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Obtain written authorization from the client

Option A is correct because written authorization from the client is a legal and ethical prerequisite before any vulnerability scanning; without it, the tester could be committing unauthorized access under laws such as the CFAA. Option B is correct because defining the scope and rules of engagement establishes which IP ranges, hosts, and time windows are permitted, preventing accidental disruption of production systems or scanning of out-of-scope assets. Option D is correct because vulnerability scanners rely on up-to-date plugin/signature databases (e.g., Nessus plugins, OpenVAS NVTs) to accurately detect current CVEs; outdated signatures produce false negatives and unreliable results. Option C is incorrect because scanning during peak business hours risks service degradation and is generally avoided unless explicitly authorized in the rules of engagement. Option E is incorrect because running every available exploit module is not a pre-scan consideration and would exceed the typical scope of a vulnerability scan, potentially causing damage and violating engagement boundaries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Obtain written authorization from the client

    Why this is correct

    Written authorization is the foundational legal safeguard that distinguishes a legitimate penetration test from unauthorized access under statutes such as the CFAA or Computer Misuse Act. A signed Statement of Work or Rules of Engagement, detailing exact targets and timeframes, provides the pentester with a formal defense against civil and criminal liability. Without this document, even a well-intentioned scan can be treated as a cyber intrusion, making it the single most critical pre-scan requirement.

  • ✓

    Define the scope and rules of engagement

    Why this is correct

    Defining scope and rules of engagement is a pre-engagement activity that precisely enumerates target IP ranges, domains, hosts, and approved testing techniques, ensuring the scanner does not traverse into third-party infrastructure or critical production systems. The rules also specify acceptable scan times, intensity limits, and escalation procedures for when critical findings are discovered, directly reducing the risk of unintended downtime and legal overreach during the assessment.

  • ✗

    Perform the scan during peak business hours

    Why it's wrong here

    Running a vulnerability scan during peak business hours is contraindicated because active scanning generates significant network traffic, consumes host resources, and can trigger resource exhaustion or disruptive IPS/IDS responses. Operational best practice is to schedule scans during defined maintenance windows or off-peak hours to avoid impacting end users and to prevent security alerts from being falsely triggered by the scanner's own activity, which dilutes the value of the assessment.

  • ✓

    Ensure the scanning tool is updated with latest signatures

    Why this is correct

    Keeping the vulnerability scanner's signature database current is essential for detecting recently disclosed CVEs, as scanners match service versions and banners against a set of plugins that are frequently updated. Using a stale signature set can yield false negatives for emergent vulnerabilities—such as new remote code execution flaws—giving the client an inaccurate security posture. This step is necessary but subordinate to authorization, since even a perfectly updated scanner cannot legally be run without prior written permission.

  • ✗

    Test all available exploit modules

    Why it's wrong here

    Aggressively testing every available exploit module during a scanning phase is dangerous because exploitation attempts go beyond passive identification and can crash services, corrupt databases, or create backdoors, causing collateral damage to the target environment. Standard methodology separates vulnerability scanning from exploitation, and the latter typically requires explicit additional approval, a dedicated exploitation phase, and careful rollback planning. Indiscriminately executing exploits also violates most rules of engagement and professional ethics, as it prioritizes attack breadth over safety and control.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.