PT0-002 Engagement Management Practice Question
A penetration tester is scoping a test for a client that uses a SaaS application for customer relationship management. The client wants the tester to assess the application's security. What is the most important consideration regarding this SaaS application?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The tester should obtain explicit permission from the SaaS provider before testing
The tester must ensure that the SaaS provider's terms of service allow security testing and that permission is obtained.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application is hosted on the cloud, so it is automatically in scope
Why it's wrong here
The fact that an application is hosted in the cloud does not, by itself, place it within the scope of a penetration test. In a SaaS model, the provider owns and controls the underlying infrastructure, so testing the application may affect the provider's shared environment and other tenants. Authorization must be derived from explicit legal permission from the provider, not from the mere deployment location. Without such permission, testing could violate the provider's terms of service and applicable computer fraud laws.
- ✓
The tester should obtain explicit permission from the SaaS provider before testing
Why this is correct
When a client uses a third-party SaaS application, the client is only a subscriber and does not own the application's infrastructure or code. The provider retains control over the platform, so any active security testing that targets the application must be explicitly authorized by the provider. This authorization typically takes the form of a written agreement, a penetration-testing rider in the service contract, or a documented engagement with the provider. Without the provider's explicit permission, the tester would be performing unauthorized access against a system they do not own, which could be illegal and could impact other tenants.
- ✗
The tester should only test the client's configuration of the SaaS application
Why it's wrong here
Restricting testing to the client's configuration of the SaaS application does not automatically make it permissible. Many SaaS providers' terms of service explicitly prohibit any form of security testing, even within a tenant's own configuration, because it may still exercise the provider's backend APIs, shared authentication mechanisms, or core application logic. The client does not have the authority to authorize testing of infrastructure or code that the provider owns. Even configuration-level testing can inadvertently expose or stress components outside the client's tenancy, so the tester must verify that the provider's acceptable use policy or testing clause allows such activity.
- ✗
The tester can test the application as long as the client provides administrative credentials
Why it's wrong here
Possessing administrative credentials for the SaaS application gives the tester access but does not grant legal or ethical authorization to perform penetration testing. Credentials are an authentication mechanism, not an authorization grant; the right to test must come from the system owner or an explicit contract. The client, as a tenant, cannot unilaterally authorize testing of the provider's infrastructure, and the provider may not have consented to any active testing. Additionally, using administrative credentials to perform invasive tests could violate the provider's cloud acceptable use policy and may cause service disruption for other tenants, leading to legal liability.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.