Courseiva
Engagement Management →mediumMultiple Select

PT0-002 Engagement Management Practice Question

A penetration tester is scoping a network penetration test for a client that uses multiple third-party services. Which TWO of the following are correct actions regarding third-party services? (Select TWO.)

⚠ Common exam trap

Many exam-takers assume third-party services are automatically in scope because they are part of the client's infrastructure, but the exam tests the legal and contractual necessity of obtaining explicit written permission before testing any external system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exclude third-party services from testing unless explicitly authorized

Option D is correct because third-party services are owned and operated by external providers, so they must be excluded from the engagement scope unless the client has explicitly authorized testing of them, typically through contractual agreements or written consent. Option E is correct because testing a third-party provider's infrastructure without that provider's written permission is unauthorized access, so the tester must obtain explicit written authorization from each provider before any testing occurs. Option A is wrong because including all third-party services without restriction would authorize testing of systems the client does not own or control, creating legal and contractual violations. Option B is wrong because assuming third-party services are automatically out of scope is not a valid scoping decision; they may be in scope if proper authorization exists. Option C is wrong because testing a third-party service without informing the provider is unauthorized and unethical, regardless of the client's request.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Include all third-party services in scope without restriction

    Why it's wrong here

    Including all third-party services in scope without restriction is invalid because the penetration tester's authority derives only from the client and the written authorization from the third-party provider. Unrestricted inclusion could reach into shared multi-tenant infrastructures, creating civil and criminal liability under the CFAA and equivalent laws, and could disrupt web services beyond the contractual perimeter. The scope boundary must be negotiated and documented for every system owner before any testing occurs, not assumed or broadly expanded.

  • ✗

    Assume that third-party services are out of scope

    Why it's wrong here

    Assuming third-party services are out of scope is unreliable because scoping must be an explicit, documented decision rather than a default inference. Many target environments depend on third-party components such as APIs, CDNs, or SaaS portals, and silently excluding them can leave critical vulnerabilities undiscovered. Conversely, if those components are later found to be within the intended test boundary, the lack of written authorization means the tester still cannot lawfully touch them. The scoping document must state each third-party system's status and the provider's permission when relevant.

  • ✗

    Test third-party services without informing the provider

    Why it's wrong here

    Testing third-party services without notifying the provider is both an ethical and legal failure: the client's permission does not extend to infrastructure owned by another organization. Unauthorized scanning or exploitation of such services can be prosecuted under the CFAA, state computer crime laws, and contractual violation of the provider's terms and conditions. Even if the test is a legitimate security assessment, the absence of explicit provider consent makes it indistinguishable from an attack, and providers often monitor their networks and will pursue legal remedies.

  • ✓

    Exclude third-party services from testing unless explicitly authorized

    Why this is correct

    The correct default with third-party infrastructure is to exclude it from testing unless the provider has explicitly authorized it, because a penetration test's authorization is specific to the systems controlled and operated by the client. This conservative boundary prevents an otherwise legal engagement from crossing into systems owned by another party, thereby avoiding unauthorized access charges and preserving the tester's legal standing. If a critical third-party component must be assessed, a scoping change with written permission should be executed before any packets are sent.

  • ✓

    Obtain written permission from each third-party provider before testing

    Why this is correct

    Obtaining written permission from each third-party provider is the proper path when those systems need to be included in the test, because it converts a potentially illegal act into an authorized security assessment. The written permission should specify the testing window, IP ranges, allowed activities, and emergency contacts, and should complement the client's authorization rather than replace it. Without that separate, documented consent, any testing directed at the provider's infrastructure exposes the tester and the client to legal liability even if the client explicitly asked for the test.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.