Courseiva
Engagement Management →hardMultiple Select

PT0-002 Engagement Management Practice Question

A penetration tester is preparing for a web application penetration test. The client application is hosted on a cloud platform that serves multiple tenants. Which THREE of the following are critical legal and scoping considerations?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Understand how the client's data privacy policies affect handling of any discovered data

Legal considerations include authorization from the cloud provider, handling sensitive data, and defining permissible testing methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Include a clause in the SOW that the tester is not liable for any data exposure

    Why it's wrong here

    Liability disclaimers in an SOW are standard contract terms but do not serve as a scoping consideration. Proper scoping is about defining authorized targets, time windows, and attack techniques, not about insulating the tester from consequences. Without explicit authorization boundaries, even a liability clause cannot shield the tester from legal exposure.

  • ✓

    Understand how the client's data privacy policies affect handling of any discovered data

    Why this is correct

    During testing, you may encounter PII, PHI, or other sensitive data. The client's data privacy policies and applicable regulations (GDPR, HIPAA, CCPA) dictate how that data must be handled, stored, and reported. Failure to comply can turn a routine pentest into a data breach with legal consequences. Therefore, understanding these policies is a crucial part of scoping and authorization.

  • ✓

    Define the types of attacks allowed (e.g., SQL injection, XSS) in the rules of engagement

    Why this is correct

    The rules of engagement (ROE) must clearly delineate which attack techniques are permissible, whether they include destructive payloads, and whether denial-of-service (DoS) testing is allowed. This prevents misunderstandings that could lead to service disruption or legal disputes. For example, SQL injection may be allowed but only with read-only queries; XSS might be allowed but without session hijacking. This specificity ensures that both the tester and the client have a shared understanding of boundaries.

  • ✓

    Ensure the cloud provider has granted permission for the test

    Why this is correct

    Many cloud providers require prior written authorization for penetration tests, especially for certain services (e.g., AWS, Azure, GCP) and have specific testing policies. Testing without provider approval can violate the Acceptable Use Policy and trigger account suspension, or even legal action under laws like the CFAA. Therefore, obtaining the cloud provider's consent is an essential part of scope and authorization, often arranged through a specific process like AWS Penetration Testing Policy or Azure Penetration Testing Rules.

  • ✗

    Test all tenant data to ensure comprehensive coverage

    Why it's wrong here

    In a multi-tenant environment, the tester must only access data belonging to the authorized client. Testing other tenants' data constitutes unauthorized access, violating the CFAA, GDPR, and possibly the cloud provider's terms. Comprehensive coverage should be limited to the client's own data and resources, not across tenants. The scope must explicitly define the tenant and any shared infrastructure boundaries.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.