mediumMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration testing firm is hired to assess a…
A penetration testing firm is hired to assess a client's network that includes both internal servers and external cloud-based services. The client wants to test only the internal network due to compliance concerns about testing cloud infrastructure. Which of the following should the penetration tester MOST strongly emphasize during the scoping meeting?
⚠ Common exam trap
Many candidates choose Option A because it sounds technically aggressive and 'security-first,' but the PT0-002 exam tests the ability to prioritize scoping discussions based on client-defined constraints and risk communication, not on unsupported claims about vulnerability prevalence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
That the test will not provide a complete risk picture without cloud components
The scope of a penetration test directly determines the validity of its risk assessment. Excluding cloud services creates a significant blind spot, as the client's attack surface includes both internal servers and external cloud-based services; without testing the cloud components, the test cannot provide a complete risk picture. The penetration tester must emphasize this limitation during scoping to ensure the client understands that the final report will not reflect the full security posture of their hybrid environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
That cloud services are often the most vulnerable and should be included for a thorough test
Why it's wrong here
This option distracts from the actual scoping issue. While cloud assets can indeed introduce significant risk, asserting that they are 'most vulnerable' is an unverified generalization and shifts focus away from the fact that the current engagement is incomplete. The professional response is to clearly document the scale and limitations, not to argue for expanding scope with unsupported claims.
- ✓
That the test will not provide a complete risk picture without cloud components
Why this is correct
This is the correct message because it directly addresses the inherent limitation of the assessment. Without cloud components, the test covers only a subset of the attack surface, so any conclusion about overall security posture would be premature. This communicates that on-prem findings must not be interpreted as an enterprise-wide risk assessment, and it sets expectations for follow-up work.
- ✗
That the client can always test cloud services later in a separate engagement
Why it's wrong here
This is wrong because it defers the issue rather than resolving it, and there's no guarantee a separate engagement will be funded or scheduled. It also fails to inform the client that the current test's conclusions will be incomplete, which could lead to a false sense of security. The tester's responsibility is to frame the current engagement's limitations now, not to assume future engagements will fill the gap.
- ✗
That compliance concerns are unfounded and the test should proceed anyway
Why it's wrong here
This is wrong because compliance constraints (e.g., data residency, regulatory restrictions) are legitimate reasons for excluding cloud assets, and ignoring them could expose the client to legal penalties. A penetration tester must operate within the agreed scope and legal boundaries; suggesting that compliance is unfounded undermines trust and may invalidate the assessment's authorization. The correct approach is to acknowledge the constraints and plan the test around them.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.