Courseiva
Engagement Management →mediumMultiple Select

PT0-002 Engagement Management Practice Question

A penetration testing firm is scoping a network penetration test for a client. The client has provided a list of IP ranges and subnets. Which TWO of the following should the tester consider when defining the scope?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify any third-party hosted services within the provided IP ranges and obtain explicit permission

Scoping must distinguish in-scope vs out-of-scope assets and address third-party services that require permission.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identify any third-party hosted services within the provided IP ranges and obtain explicit permission

    Why this is correct

    When an IP range is provided for a network penetration test, it may contain addresses owned by the client but operated by third parties, such as cloud providers, CDNs, or SaaS vendors. Testing those systems requires separate written authorization from the actual owner, because the client's permission does not extend to third-party infrastructure. You must therefore proactively identify any third-party hosted services within the provided ranges and obtain explicit permission before active testing to stay within legal and ethical boundaries.

  • ✓

    Define which IP ranges are out of scope and document them

    Why this is correct

    Scoping is the process of explicitly defining which systems are in scope and which are out of scope. Documenting out-of-scope IP ranges is a critical control that prevents testers from accidentally targeting systems not covered by the Rules of Engagement. This documentation serves as a formal reference for the testing team and the client, helping to avoid unauthorized access, service disruption, or contractual violations. Without clear documentation, even a well-intentioned tester may exceed the agreed boundaries.

  • ✗

    All IP addresses owned by the client are in scope

    Why it's wrong here

    While the client may own the IP addresses in their allocations, not every owned IP is automatically testable. Certain assets may be excluded for business reasons, such as production systems with high availability requirements, or they may be under contractual restrictions with third-party partners who share the same network. The scope of a penetration test is defined by the engagement objectives and the client's risk tolerance, not simply by ownership. Therefore, assuming all owned IPs are in scope is incorrect and could lead to unintended outages or legal issues.

  • ✗

    Test all IP addresses regardless of ownership to ensure complete coverage

    Why it's wrong here

    Testing IP addresses that are not owned or controlled by the client requires authorization from the actual owner. The client's authorization covers only their own assets and explicitly granted third-party permissions, not the entire internet. Conducting tests on non-owned IPs without permission is illegal in many jurisdictions, for example under computer fraud and abuse laws, and can expose the tester and the client to criminal and civil penalties. Complete coverage must be achieved through proper scoping, not by indiscriminately testing any reachable address.

  • ✗

    Include all subnets that are routable from the internet

    Why it's wrong here

    The fact that a subnet is routable from the internet only means that packets can reach it; it says nothing about ownership or authorization. Many routable subnets belong to ISPs, cloud providers, or other organizations that are not parties to the engagement. Penetration testing without explicit permission from the owner of those addresses is both unethical and illegal, even if the subnet is adjacent to in-scope systems. Therefore, scope must be determined by documented client authorization and asset inventory, not by technical reachability or internet routing tables.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.