mediumMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration testing firm is contracted to test…
A penetration testing firm is contracted to test a cloud-based infrastructure. The client uses a shared responsibility model. Which of the following should be clarified in the rules of engagement to avoid legal issues?
⚠ Common exam trap
CompTIA often tests the misconception that operational security tasks like patching or encryption are the primary legal concerns in a shared responsibility model, when in fact the critical legal issue is obtaining explicit authorization from the cloud provider to avoid violating their terms of service or anti-hacking laws.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Whether the tester needs authorization from the cloud provider
In a shared responsibility model, the cloud provider is responsible for the security of the cloud, while the customer is responsible for security in the cloud. However, penetration testing activities may violate the cloud provider's terms of service or acceptable use policy, potentially triggering legal action. Therefore, obtaining explicit authorization from the cloud provider is critical to ensure the tester's actions are legally permitted and to avoid liability for unauthorized access under laws like the Computer Fraud and Abuse Act (CFAA).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Who is responsible for patching the operating system
Why it's wrong here
Patching responsibility is a shared responsibility model detail that determines which party updates the OS, but it does not affect the legal right to test. A penetration tester must obtain authorization from the system owner and possibly the cloud provider regardless of who performs patching. This operational factor influences the scope of potential vulnerabilities but is not a prerequisite for authorization to conduct the test.
- ✓
Whether the tester needs authorization from the cloud provider
Why this is correct
Cloud providers like AWS, Azure, and GCP often require explicit written authorization before penetration testing, and testing without it can violate the provider's acceptable use policy or the Computer Fraud and Abuse Act (CFAA). Obtaining provider approval is a legal prerequisite that also ensures the tester's activities are recognized as authorized, protecting against claims of unauthorized access. This authorization is independent of the customer's consent and must be secured before testing the cloud infrastructure.
- ✗
The encryption method for data at rest
Why it's wrong here
Data-at-rest encryption is a security control that protects stored data, and while it affects how the tester handles or interprets data, it does not determine whether the tester has legal permission to test. Authorization hinges on contractual agreements, consent from the resource owner, and compliance with the cloud provider's testing policies. Encryption settings might complicate the technical assessment but have no bearing on the legal validity of the engagement.
- ✗
The backup strategy for logs
Why it's wrong here
The log backup strategy is an operational process that defines how logs are retained and protected for post-incident analysis, but it is unrelated to the legal authorization required to conduct a penetration test. Authorization is established through contracts, service agreements, and explicit approval from the cloud provider, not through how logs are managed. While logs are valuable for evidence, their backup configuration does not influence whether testing is legally sanctioned or whether the provider must be notified.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Liability
Liability in IT refers to the legal and financial responsibility an organization or individual bears for data breaches, security failures, or compliance violations arising from inadequate planning and scoping of systems and processes.
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
About these practice questions
One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.