PT0-002 Engagement Management Practice Question
A penetration tester is preparing for a social engineering engagement. The client has requested that the tester attempt to gain access to the building by impersonating a delivery person. Which of the following should the tester obtain from the client before conducting the test?
⚠ Common exam trap
The trap here is thinking that an NDA or security policy is sufficient, but only the get-out-of-jail letter authorizes physical entry and protects against trespassing charges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A get-out-of-jail letter
For physical social engineering engagements, the tester must obtain a get-out-of-jail letter from the client. This document authorizes the tester to be on the premises and protects them from legal action if they are caught. It is essential for legal protection and should be carried at all times during the engagement. Other documents like NDAs or security policies do not provide this authorization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A copy of the client's security policy
Why it's wrong here
A copy of the client's security policy may provide useful context about physical security controls, but it does not authorize the tester to enter the premises. The tester needs a get-out-of-jail letter to legally protect themselves during the engagement. Without it, the tester could face legal consequences for trespassing, even if the test is authorized by a manager.
- ✗
A non-disclosure agreement (NDA)
Why it's wrong here
An NDA protects confidential information but does not authorize physical entry or protect against trespassing charges. The tester needs a get-out-of-jail letter to prove that they are authorized to be on the premises. The NDA is usually signed before the engagement but is not sufficient for physical security testing. The get-out-of-jail letter is the specific document required.
- ✗
A list of employee names and phone numbers
Why it's wrong here
A list of employee names and phone numbers is typically used for phishing or vishing attacks, not for physical impersonation. While it could be useful for pretexting, it is not the primary document needed for physical entry. The tester needs explicit authorization to enter the premises, which is provided by the get-out-of-jail letter. Without it, the tester could be arrested for trespassing.
- ✓
A get-out-of-jail letter
Why this is correct
The get-out-of-jail letter is essential for physical social engineering engagements. It authorizes the tester to be on the premises and protects them from legal action if they are caught impersonating a delivery person. It should be signed by an authorized client representative and kept on the tester's person during the engagement. This document is critical for legal protection and proof of authorization.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.