mediumMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration testing firm has been hired to test…
A penetration testing firm has been hired to test the internal network of a large enterprise. During the scoping meeting, the client states that they want to include all IP ranges, including those used by the HR department's sensitive systems. The tester should recommend which of the following to minimize business impact and avoid disruption?
⚠ Common exam trap
It's easy for candidates to choose Option C (passive reconnaissance) thinking it avoids disruption entirely, but they overlook that passive techniques cannot fulfill the test's objective of identifying exploitable vulnerabilities, which requires active interaction with the target systems.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform the test during off-peak hours and provide prior notification
Performing the test during off-peak hours and providing prior notification minimizes business impact by reducing the likelihood of disrupting critical HR operations during normal business hours. This approach aligns with the scoping requirement to include all IP ranges while allowing the client to prepare for potential service interruptions, such as those caused by active scanning techniques like TCP SYN scans or service enumeration. Prior notification ensures that HR staff can take precautions, such as backing up sensitive data or pausing batch jobs, thereby avoiding data corruption or system unavailability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exclude the HR department's IP range from the test
Why it's wrong here
Excluding the HR department's IP range from the authorized scope directly contradicts the client's requirement to test all in-scope IP ranges and creates an exploitable blind spot. HR systems often store highly sensitive PII, payroll data, and confidential employee records, making them a prime target for lateral movement from other compromised segments. By removing this subnet, the pentest fails to validate whether an attacker who initially breaches another system could pivot into HR and exfiltrate critical data, thereby leaving the organization's most valuable data assets unassessed.
- ✓
Perform the test during off-peak hours and provide prior notification
Why this is correct
Scheduling the engagement during off-peak hours, such as nights or weekends, reduces the risk of operational disruption to critical HR processes like payroll runs, benefits processing, and employee self-service transactions. Providing prior notification to HR allows their IT and security teams to review planned test activities, adjust monitoring thresholds to avoid false positives, and ensure that any system failures can be distinguished from test-induced incidents. This approach aligns with proper change management and deconfliction procedures, ensuring that valid business activities are not mistaken for intrusions while maintaining full coverage of the assigned scope.
- ✗
Use only passive reconnaissance techniques on the HR systems
Why it's wrong here
Restricting the assessment to passive reconnaissance techniques—such as OSINT gathering, network traffic capture, and certificate transparency analysis—prevents the test from actively engaging with HR systems to identify exploitable vulnerabilities. A penetration test requires active scanning, service enumeration, vulnerability verification, and safe exploitation attempts to demonstrate real-world risk and assess the effectiveness of existing security controls. Without these active steps, many flaws—including unpatched CVEs, misconfigured authentication, and injection points—can remain undetected, so this approach fails to meet the objective of a comprehensive internal penetration test.
- ✗
Include the HR systems but require written authorization from HR management
Why it's wrong here
Securing written authorization from HR management addresses the legal and contractual aspects of the engagement but does nothing to mitigate the operational risk of testing systems that support time-sensitive HR functions. Unlike prior notification and off-peak scheduling, this measure fails to protect availability, as active test traffic during business hours could trigger outages, corrupt batch jobs, or disrupt employee access to HR applications. Therefore, while authorization is a necessary prerequisite, it is insufficient on its own to satisfy the client's requirement to minimize business impact during the test.
Visual reference
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Enumeration
Enumeration is the systematic process of extracting detailed information about a target system, such as user accounts, network shares, services, and configurations, used during the reconnaissance phase of a security assessment.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.