Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is scoping a test for a…

A penetration tester is scoping a test for a multinational company that must comply with GDPR. The tester wants to ensure that any personal data captured during the test is handled appropriately. Which document should be reviewed?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data processing agreement

A data processing agreement (DPA) outlines how personal data is processed and protected, which is essential for GDPR compliance. An NDA covers confidentiality but not data processing specifics. An authorization letter grants permission, and a test plan is technical.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Test plan

    Why it's wrong here

    A test plan is an internal document that details the technical procedures, scope, and timelines for executing the penetration test. It does not establish any legal framework for how personal data encountered during the assessment must be handled, stored, or protected. Therefore, while valuable for coordinating the engagement, it cannot satisfy the contractual and regulatory data-processing requirements mandated by GDPR.

  • ✗

    Authorization letter

    Why it's wrong here

    An authorization letter grants the penetration tester legal permission to perform intrusive testing against specified systems, effectively defining the boundaries of the engagement. However, it focuses solely on consent to attack, not on the safeguards or conditions for processing any personal data that may be accessed or captured. It does not designate the tester's role as a processor or obligate them to comply with GDPR principles such as data minimization or security of processing.

  • ✓

    Data processing agreement

    Why this is correct

    A data processing agreement (DPA) is a legally binding contract that formally defines the relationship between the client (controller) and the penetration testing firm (processor) under Article 28 of GDPR. It specifies the purpose, duration, and types of personal data to be processed, along with security measures, breach notification duties, and sub-processing restrictions. Without a DPA, the testing firm lacks the contractual basis to lawfully handle personal data during the assessment, making it essential for GDPR compliance.

  • ✗

    Non-disclosure agreement

    Why it's wrong here

    A non-disclosure agreement (NDA) is designed to protect confidential information from unauthorized disclosure, but it does not regulate how personal data is processed. It is silent on critical GDPR requirements such as lawful basis, data retention limits, data subject rights, and technical security controls. Consequently, an NDA only addresses the confidentiality of the information, not the broader data-processing obligations that apply when a penetration test accesses personal data.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.