Courseiva
Engagement Management →hardMultiple Select

PT0-002 Engagement Management Practice Question

A penetration testing company is planning a social engineering engagement for a client. The engagement includes phishing and physical tailgating. Which THREE of the following should be clearly defined in the Rules of Engagement? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The conditions under which the test must be stopped immediately

RoE should address personnel scope, emergency stop conditions, and specific techniques allowed; vulnerabilities and deliverables are part of SOW.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The format of the final report

    Why it's wrong here

    The format of the final report is a deliverable specification typically defined in the project's statement of work (SOW) or contract, outlining sections, structure, and presentation standards. It does not govern the tester's real-time execution constraints, legal boundaries, or the authority to perform specific techniques. Whereas RoE defines the 'how' and 'when' of testing activities, report formatting is a contractual expectation for the final artifact, not a boundary condition.

  • ✗

    The specific vulnerabilities to be exploited

    Why it's wrong here

    Specific vulnerabilities to be exploited are never predetermined in RoE; they are empirically discovered during the engagement through reconnaissance and scanning. Predefining them would convert the assessment from an authentic exercise into a scripted compliance check, invalidating the test's realism and the client's insight into real attacker paths. RoE instead places constraints on exploitation techniques (e.g., no zero-days, no DoS), leaving the actual vulnerabilities emergent.

  • ✓

    The conditions under which the test must be stopped immediately

    Why this is correct

    Emergency stop criteria, often called 'cease-and-desist' or 'safety stop' conditions, are an indispensable RoE section that enumerates triggering events such as evidence of life-threatening incidents, unexpected system catastrophic failures, or unauthorized access to protected health/financial data. This clause clarifies that the tester's authority to act is revocable in real time and defines the chain of communication for immediate shutdown. Absent this, the client retains no operational control over a live, rolling attack scenario, which is both a legal and safety hazard.

  • ✓

    The types of social engineering attacks allowed (e.g., phishing, vishing, tailgating)

    Why this is correct

    Social engineering techniques carry distinct legal and human-risk profiles, making explicit authorization per attack vector mandatory. RoE must enumerate whether phishing (simulated or otherwise), vishing, smsishing, physical tailgating, or in-person impersonation is permitted, along with any restrictions on impersonating law enforcement or authorities. Specifying these types is not incidental; it ensures informed consent because each technique triggers different duties of care, liability, and harm-prevention measures (e.g., phishing needs alert banners, tailgating must avoid false arrest).

  • ✓

    The list of employees and contractors who are in scope for social engineering

    Why this is correct

    Personnel scope in social engineering RoE must precisely enumerate the targeted departments, individual job functions, or named individuals/contractors, because unlike network scope, human targets have privacy expectations and employment-law protections. Targeting an unnamed or out-of-scope person could constitute stalking, harassment, or workplace misconduct, turning a sanctioned test into a tort. The RoE should also specify notification rules (e.g., whether targets can be announced after the test) and any consent records required from the client's employee representatives.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.