Courseiva
mediumMultiple Choice

PT0-002 Practice Question: Defines authorized targets and excluded systems.

A penetration tester is preparing the final report. The client's legal team requests a document that outlines the scope, limitations, and any data handling procedures to comply with regulatory requirements. Which section of the report should include this information?

⚠ Common exam trap

Many exam-takers confuse the Executive Summary with a catch-all for legal disclaimers, but the exam expects the precise placement of contractual and compliance details in the Scope and Rules of Engagement section.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scope and Rules of Engagement

The Scope and Rules of Engagement section is the correct location for documenting the scope, limitations, and data handling procedures because it formally defines the boundaries of the penetration test, including authorized targets, testing windows, and legal constraints. This section ensures compliance with regulatory requirements by specifying how data is collected, stored, and disposed of, which is critical for audits and legal review.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Executive Summary

    Why it's wrong here

    The Executive Summary is written for non-technical management, focusing on overall risk exposure, business impact, and high-level recommendations. It deliberately omits contractual specifics such as authorized IP ranges, data retention rules, and legal boundaries that must be documented elsewhere. Therefore, it is not the correct section for detailed legal and procedural constraints.

  • ✗

    Methodology

    Why it's wrong here

    The Methodology section records the exact tools, techniques, and procedures used during reconnaissance, scanning, exploitation, and post-exploitation, along with timestamps and settings. Its purpose is to ensure the assessment is reproducible and transparent for technical reviewers, not to define the legal perimeter of authorization or how sensitive data is handled. Thus, Methodology is not where scope and data-handling clauses belong.

  • ✓

    Scope and Rules of Engagement

    Why this is correct

    The Scope and Rules of Engagement section is the formal, legally binding part of the report that enumerates authorized assets, allowed testing windows, exclusion lists, and prohibited techniques. It also specifies data handling and retention procedures to satisfy legal and compliance mandates such as GDPR or PCI-DSS. This makes it the correct section for documenting the engagement's constraints and authorization.

  • ✗

    Technical Findings

    Why it's wrong here

    The Technical Findings section catalogs each vulnerability with severity ratings, supporting evidence, and step-by-step remediation advice for technical teams. It concentrates on what was discovered and how to fix it, not on the overarching test boundaries or data handling requirements. Consequently, it is not the place to document legal and procedural constraints.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.