mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is scoping a test for a…
A penetration tester is scoping a test for a multinational company that must comply with GDPR. The tester wants to ensure that any personal data captured during the test is handled appropriately. Which document should be reviewed?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data processing agreement
A data processing agreement (DPA) outlines how personal data is processed and protected, which is essential for GDPR compliance. An NDA covers confidentiality but not data processing specifics. An authorization letter grants permission, and a test plan is technical.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Test plan
Why it's wrong here
A test plan is an internal document that details the technical procedures, scope, and timelines for executing the penetration test. It does not establish any legal framework for how personal data encountered during the assessment must be handled, stored, or protected. Therefore, while valuable for coordinating the engagement, it cannot satisfy the contractual and regulatory data-processing requirements mandated by GDPR.
- ✗
Authorization letter
Why it's wrong here
An authorization letter grants the penetration tester legal permission to perform intrusive testing against specified systems, effectively defining the boundaries of the engagement. However, it focuses solely on consent to attack, not on the safeguards or conditions for processing any personal data that may be accessed or captured. It does not designate the tester's role as a processor or obligate them to comply with GDPR principles such as data minimization or security of processing.
- ✓
Data processing agreement
Why this is correct
A data processing agreement (DPA) is a legally binding contract that formally defines the relationship between the client (controller) and the penetration testing firm (processor) under Article 28 of GDPR. It specifies the purpose, duration, and types of personal data to be processed, along with security measures, breach notification duties, and sub-processing restrictions. Without a DPA, the testing firm lacks the contractual basis to lawfully handle personal data during the assessment, making it essential for GDPR compliance.
- ✗
Non-disclosure agreement
Why it's wrong here
A non-disclosure agreement (NDA) is designed to protect confidential information from unauthorized disclosure, but it does not regulate how personal data is processed. It is silent on critical GDPR requirements such as lawful basis, data retention limits, data subject rights, and technical security controls. Consequently, an NDA only addresses the confidentiality of the information, not the broader data-processing obligations that apply when a penetration test accesses personal data.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.