PT0-002 Engagement Management Practice Question
A penetration testing company is scoping a test for a client. The client wants to ensure that testing does not impact production systems. Which TWO of the following are appropriate scoping considerations? (Select TWO.)
⚠ Common exam trap
Watch out — candidates often confuse 'defining specific test windows' with a scheduling detail rather than a scoping control, but it directly prevents testing during production peak hours, thus protecting production systems from impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Testing on a staging environment
Option A is correct because testing on a staging environment allows the penetration testers to exercise the same application and infrastructure components without touching live production systems, directly satisfying the client's requirement that production not be impacted. Option E is correct because defining specific test windows constrains testing to agreed low-risk periods, which limits the chance that active scanning, exploitation, or traffic spikes will disrupt production services and gives the client control over when impact is possible. Option B is not appropriate because including all third-party services expands scope beyond the client's control and can affect external production systems the client does not own. Option C is not appropriate because allowing unlimited testing hours removes the scheduling control needed to protect production during peak or business-critical times. Option D is not appropriate because testing all IP addresses in the organization would include production hosts, contradicting the goal of avoiding production impact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Testing on a staging environment
Why this is correct
Staging environments replicate production with controlled data and no live users, so security tests can safely simulate attacks without impacting business operations. They allow for thorough testing of vulnerabilities like injection or authentication flaws in a realistic but isolated setting. Scoping to a staging environment reduces legal and operational risks while still validating security controls effectively.
- ✗
Including all third-party services
Why it's wrong here
In penetration testing scoping, third-party services are typically outside the authorized boundary unless explicitly listed and approved by their owners. Testing them without written authorization from the provider violates contracts and can lead to legal action, and their inclusion often exposes data flows where the client has no direct control or visibility. Scoping should restrict testing to assets owned by the client or those with explicit third-party consent.
- ✗
Allowing unlimited testing hours
Why it's wrong here
Unlimited testing hours remove time-based controls that prevent testers from performing intrusive actions during business hours, increasing the chance of service disruption and inadvertently triggering defenders. Scoping should define clear start and end times along with blackout windows to avoid impact on critical operations. Without such limits, testing becomes harder to contain and more likely to escalate into a denial-of-service situation.
- ✗
Testing all IP addresses in the organization
Why it's wrong here
Not all IP addresses are appropriate targets; testing the entire range could inadvertently hit production systems, partner infrastructure, or network devices that are outside the agreed scope. Even if ownership is confirmed, broad scanning can cause significant downtime and violate service-level agreements. Scoping should identify specific, authorized targets, explicitly excluding anything that could affect production or third-party environments.
- ✓
Defining specific test windows
Why this is correct
Test windows sync testing activities with maintenance periods or low-traffic times, minimizing operational impact and ensuring consistent availability of systems. They also help coordinate with incident response teams, who can distinguish test traffic from real attacks and avoid unnecessary alerts. Establishing well-defined windows is a core scoping practice that protects the client's uptime and the legal credibility of the engagement.
Go deeper
Related to this question
Learn chapter
Masscan and ZMap for Fast Port Scanning
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.