mediumMultiple Choice
PT0-002 Practice Question: A penetration testing firm is hired to assess a…
A penetration testing firm is hired to assess a client's hybrid infrastructure with on-premises and cloud servers in multiple regions. The client specifies testing only the on-premises systems due to budget and compliance. Which of the following should the tester emphasize in the rules of engagement (ROE)?
⚠ Common exam trap
Many exam-takers think they need cloud provider approval or network diagrams to understand the environment, but the key is respecting the client's explicit scope limitation by excluding cloud assets in the ROE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Explicit exclusion of all cloud-based assets
The client explicitly restricted testing to on-premises systems due to budget and compliance. The rules of engagement (ROE) must clearly define the authorized scope to prevent accidental testing of cloud assets, which could violate the contract and potentially breach the cloud provider's terms of service. Option B is correct because explicitly excluding all cloud-based assets ensures the tester does not touch any cloud resources, aligning with the client's constraints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detailed network diagrams of the cloud environment
Why it's wrong here
Since the ROE explicitly excludes cloud-based assets, detailed network diagrams of the cloud environment are irrelevant to the authorized testing boundaries. Including them would be wasted effort and could inadvertently suggest that cloud resources are testable, increasing the risk of scope creep. Moreover, such diagrams often contain sensitive architectural details that are unnecessary for an assessment confined to on-premises infrastructure, potentially creating data-handling concerns.
- ✓
Explicit exclusion of all cloud-based assets
Why this is correct
The Rules of Engagement must unambiguously delineate the authorized testing surface. Explicitly excluding cloud-based assets prevents the tester from inadvertently probing systems that are outside the contracted scope, which could constitute unauthorized access and violate cloud provider terms of service or data protection regulations. This clarity also aligns expectations between the client and tester, mitigating the risk of scope creep and ensuring that any findings are confined to the intended on-premises environment.
- ✗
Approval from the cloud service provider
Why it's wrong here
While certain cloud providers may have their own authorization procedures for permitted testing (e.g., penetration testing approval forms), such approval is not a required element of the Rules of Engagement document. The ROE focuses on the mutual agreement between the client and the testing firm regarding the exact scope, legal boundaries, and technical constraints of the engagement. Relying on provider approval as a substitute for an explicit out-of-scope declaration could leave the tester without clear guidance on hybrid cloud interfaces, such as VPN gateways or shared VPCs, that might still be reachable.
- ✗
A list of all cloud API endpoints
Why it's wrong here
Enumerating cloud API endpoints is counterproductive when cloud assets are explicitly excluded from the engagement. Such a list would provide no value to the tester and could be misconstrued as an invitation to probe those interfaces, especially since many cloud APIs are internet-accessible and would appear as attack surface during reconnaissance. A proper ROE should instead specify which systems are out of scope and how to handle any cloud resources that are encountered incidentally, leaving endpoint enumeration to the actual testing phase if permitted.
Go deeper
Related to this question
Learn chapter
Mobile Application Testing
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.