hardMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration testing firm is contracted to…
A penetration testing firm is contracted to perform an external test of a company's web applications. During the scoping meeting, the client mentions that they use a CDN and WAF provided by a third party. The client wants the test to accurately reflect the security of their backend servers behind these protections. What should the tester recommend?
⚠ Common exam trap
Watch out — candidates often assume bypassing the WAF is the correct approach (Option C), but the ethical and practical method is to test the backend servers directly with client permission, not to actively circumvent security controls during the test.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtain the backend server IPs from the client and test them directly
The client wants the test to accurately reflect the security of their backend servers behind the CDN and WAF. By obtaining the backend server IPs directly, the tester can bypass the third-party protections and assess the actual security posture of the origin servers, which is the true target of the external test. This approach ensures that vulnerabilities not mitigated by the CDN/WAF are identified, aligning with the client's goal of evaluating backend security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Test the CDN and WAF as part of the scope
Why it's wrong here
Testing the CDN and WAF infrastructure owned by a third-party provider is outside the client's authoritative boundary. Even with client approval, the provider's terms of service typically prohibit active security scanning, and unauthorized testing could lead to legal liability. Additionally, such testing might disrupt shared infrastructure and impact other customers, making it an invalid scope expansion.
- ✓
Obtain the backend server IPs from the client and test them directly
Why this is correct
Obtaining the backend server IPs from the client allows the tester to directly assess the origin servers the client wants evaluated. This approach stays within the authorized scope because the client has explicit ownership and control over these systems, and bypassing the CDN/WAF is done with the client's knowledge and permission. It also avoids third-party infrastructure entirely, preventing legal and technical issues while providing accurate backend security results.
- ✗
Include a plan to bypass the WAF in the rules of engagement
Why it's wrong here
Including a WAF bypass plan in the rules of engagement is risky because the WAF is operated by a third party, and intentionally evading it could be considered an attack on that provider. The client's authorization typically does not extend to circumventing security controls owned by another entity, and the tester may not be shielded from legal consequences. Furthermore, a successful bypass could disrupt the WAF's protective service, potentially causing outages or degradation for other users.
- ✗
Only test the public-facing URLs as they are
Why it's wrong here
Testing only the public-facing URLs would exercise the CDN edge and WAF, but not the actual backend servers. Since the CDN/WAF filters, caches, and often hides the origin IPs, such tests would miss vulnerabilities specific to the backend, such as weak authentication or insecure server configurations. This approach fails to meet the client's requirement to assess backend security and could produce a false sense of security.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.