Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration tester is scoping an engagement for…

A penetration tester is scoping an engagement for a client that hosts a public-facing web application and an internal database server. The client wants to ensure that testing does not cause any disruption to the database server. Which of the following should the tester include in the rules of engagement to address this concern?

⚠ Common exam trap

It's easy for candidates to think passive reconnaissance or off-peak testing is sufficient to avoid disruption, but the CompTIA PT0-002 exam emphasizes that only explicit out-of-scope designation guarantees no interaction with a target system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Define the database server as an out-of-scope target.

Defining the database server as out-of-scope explicitly removes it from all testing activities, ensuring zero disruption as requested. This is the only option that fully prevents any interaction with the database server, including passive reconnaissance or exploitation attempts, which could still cause unintended load or queries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Specify that only passive reconnaissance techniques will be used on the database server.

    Why it's wrong here

    Passive reconnaissance still requires interacting with the network path to the database server, such as configuring a SPAN port or tapping a fiber link to capture traffic. This introduces a potential point of failure and can expose sensitive production data in transit, while also potentially triggering data-loss prevention or intrusion detection systems. Because the client requires zero disruption, any activity that touches the server's traffic or network segment is unacceptable.

  • Include a clause that the tester will not attempt to exploit any vulnerabilities on the database server.

    Why it's wrong here

    This clause only prohibits exploitation, but other phases of a pentest such as port scans, version detection, and unauthenticated enumeration send crafted packets to the database server. These can cause resource exhaustion, crash vulnerable database services, or lock out service accounts due to failed authentication attempts. Since the client demands zero disruption, merely banning exploitation is insufficient; the entire server must be off-limits.

  • Define the database server as an out-of-scope target.

    Why this is correct

    Explicitly listing the database server as out-of-scope in the rules of engagement is the only contractual and technical guarantee that no tool will send packets to it, as all scanning and testing tools can be configured with exclusion lists. This eliminates any risk of accidental disruption, data corruption, or service outage, and also protects the tester from legal and professional liability. It is the cleanest, most enforceable scoping decision.

  • Require that all testing activities be performed during off-peak hours only.

    Why it's wrong here

    Performing tests only during off-peak hours reduces the likelihood of impacting users, but it does not eliminate the risk to the database server, which may run time-sensitive batch processes, replications, or backups at night. Additionally, a malformed packet or an aggressive scan can cause an outage at any hour, and many modern databases operate globally so no true off-peak window exists. Off-peak scheduling is a mitigation, not a guarantee, so it fails the zero-disruption requirement.

About these practice questions

One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.