Courseiva
mediumMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration testing firm is contracted to test…

A penetration testing firm is contracted to test a cloud-based infrastructure. The client uses a shared responsibility model. Which of the following should be clarified in the rules of engagement to avoid legal issues?

⚠ Common exam trap

CompTIA often tests the misconception that operational security tasks like patching or encryption are the primary legal concerns in a shared responsibility model, when in fact the critical legal issue is obtaining explicit authorization from the cloud provider to avoid violating their terms of service or anti-hacking laws.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Whether the tester needs authorization from the cloud provider

In a shared responsibility model, the cloud provider is responsible for the security of the cloud, while the customer is responsible for security in the cloud. However, penetration testing activities may violate the cloud provider's terms of service or acceptable use policy, potentially triggering legal action. Therefore, obtaining explicit authorization from the cloud provider is critical to ensure the tester's actions are legally permitted and to avoid liability for unauthorized access under laws like the Computer Fraud and Abuse Act (CFAA).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Who is responsible for patching the operating system

    Why it's wrong here

    Patching responsibility is a shared responsibility model detail that determines which party updates the OS, but it does not affect the legal right to test. A penetration tester must obtain authorization from the system owner and possibly the cloud provider regardless of who performs patching. This operational factor influences the scope of potential vulnerabilities but is not a prerequisite for authorization to conduct the test.

  • Whether the tester needs authorization from the cloud provider

    Why this is correct

    Cloud providers like AWS, Azure, and GCP often require explicit written authorization before penetration testing, and testing without it can violate the provider's acceptable use policy or the Computer Fraud and Abuse Act (CFAA). Obtaining provider approval is a legal prerequisite that also ensures the tester's activities are recognized as authorized, protecting against claims of unauthorized access. This authorization is independent of the customer's consent and must be secured before testing the cloud infrastructure.

  • The encryption method for data at rest

    Why it's wrong here

    Data-at-rest encryption is a security control that protects stored data, and while it affects how the tester handles or interprets data, it does not determine whether the tester has legal permission to test. Authorization hinges on contractual agreements, consent from the resource owner, and compliance with the cloud provider's testing policies. Encryption settings might complicate the technical assessment but have no bearing on the legal validity of the engagement.

  • The backup strategy for logs

    Why it's wrong here

    The log backup strategy is an operational process that defines how logs are retained and protected for post-incident analysis, but it is unrelated to the legal authorization required to conduct a penetration test. Authorization is established through contracts, service agreements, and explicit approval from the cloud provider, not through how logs are managed. While logs are valuable for evidence, their backup configuration does not influence whether testing is legally sanctioned or whether the provider must be notified.

About these practice questions

One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.