Courseiva
mediumMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration testing firm is hired to assess a…

A penetration testing firm is hired to assess a client's network that includes both internal servers and external cloud-based services. The client wants to test only the internal network due to compliance concerns about testing cloud infrastructure. Which of the following should the penetration tester MOST strongly emphasize during the scoping meeting?

⚠ Common exam trap

Many candidates choose Option A because it sounds technically aggressive and 'security-first,' but the PT0-002 exam tests the ability to prioritize scoping discussions based on client-defined constraints and risk communication, not on unsupported claims about vulnerability prevalence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

That the test will not provide a complete risk picture without cloud components

The scope of a penetration test directly determines the validity of its risk assessment. Excluding cloud services creates a significant blind spot, as the client's attack surface includes both internal servers and external cloud-based services; without testing the cloud components, the test cannot provide a complete risk picture. The penetration tester must emphasize this limitation during scoping to ensure the client understands that the final report will not reflect the full security posture of their hybrid environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • That cloud services are often the most vulnerable and should be included for a thorough test

    Why it's wrong here

    This option distracts from the actual scoping issue. While cloud assets can indeed introduce significant risk, asserting that they are 'most vulnerable' is an unverified generalization and shifts focus away from the fact that the current engagement is incomplete. The professional response is to clearly document the scale and limitations, not to argue for expanding scope with unsupported claims.

  • That the test will not provide a complete risk picture without cloud components

    Why this is correct

    This is the correct message because it directly addresses the inherent limitation of the assessment. Without cloud components, the test covers only a subset of the attack surface, so any conclusion about overall security posture would be premature. This communicates that on-prem findings must not be interpreted as an enterprise-wide risk assessment, and it sets expectations for follow-up work.

  • That the client can always test cloud services later in a separate engagement

    Why it's wrong here

    This is wrong because it defers the issue rather than resolving it, and there's no guarantee a separate engagement will be funded or scheduled. It also fails to inform the client that the current test's conclusions will be incomplete, which could lead to a false sense of security. The tester's responsibility is to frame the current engagement's limitations now, not to assume future engagements will fill the gap.

  • That compliance concerns are unfounded and the test should proceed anyway

    Why it's wrong here

    This is wrong because compliance constraints (e.g., data residency, regulatory restrictions) are legitimate reasons for excluding cloud assets, and ignoring them could expose the client to legal penalties. A penetration tester must operate within the agreed scope and legal boundaries; suggesting that compliance is unfounded undermines trust and may invalidate the assessment's authorization. The correct approach is to acknowledge the constraints and plan the test around them.

About these practice questions

One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.