hardMultiple Choice
PT0-002 Practice Question: A penetration testing firm is hired to assess a…
A penetration testing firm is hired to assess a healthcare organization's network. The client has strict regulatory requirements (HIPAA) and wants to ensure that all patient data is protected during testing. Which scoping document should specify the data handling procedures and the destruction of any collected sensitive information?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Protection Addendum
A Data Protection Addendum (DPA) or equivalent data handling agreement is the appropriate document to define how sensitive data will be handled, stored, and destroyed. The Rules of Engagement cover authorization and constraints, but specific data protection clauses are often in a separate addendum or included in the contract. The Methodology and Scope of Work do not typically detail data destruction procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rules of Engagement
Why it's wrong here
Rules of Engagement (RoE) delineate the authorization, scope, and operational constraints for a penetration test, such as testing windows, legal boundaries, and emergency stop procedures. While RoE may reference high-level compliance obligations, they do not typically prescribe detailed data handling protocols like encryption-in-transit, retention limits, or secure destruction methods for sensitive data such as PHI. These granular data governance requirements are contractually codified in a Data Protection Addendum (DPA) rather than in the RoE document itself.
- ✗
Testing Methodology
Why it's wrong here
Testing Methodology outlines the systematic technical process an assessor will follow, including tools, techniques, and reporting standards aligned with frameworks like PTES or OSSTMM. It is an operational playbook for discovering and exploiting vulnerabilities, not a legal or procedural document governing how to handle or dispose of data encountered during testing. The methodology may implicitly affect data exposure, but it does not specify compliance-driven controls such as access restrictions or certified data sanitization, which are the domain of a DPA.
- ✓
Data Protection Addendum
Why this is correct
A Data Protection Addendum (DPA) is a legally binding contract that mandates how sensitive information such as Protected Health Information (PHI) must be guarded, processed, and ultimately destroyed in accordance with regulations like HIPAA/HITECH. In a healthcare penetration test, the DPA requires specific technical safeguards—e.g., AES-256 encryption for data at rest and in transit, role-based access limits, and NIST SP 800-88-compliant wiping before return or disposal. This precision and enforceability make the DPA the correct instrument for defining data handling, unlike broader scoping or authorization documents.
- ✗
Scope of Work
Why it's wrong here
The Statement of Work (SOW) defines the project's deliverables, milestones, resource allocation, and pricing, essentially specifying the 'what' and 'when' of the engagement. It does not address 'how' data is to be protected or destroyed, and only tangential references to data security may appear if linked to compliance clauses. Since the SOW is a project management artifact rather than a data governance instrument, it lacks the explicit legal terms for PHI handling and breach notification that a DPA provides.
Go deeper
Related to this question
Learn chapter
Mobile Application Testing
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.