Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration testing firm is scoping a test for…

A penetration testing firm is scoping a test for a client that has a hybrid infrastructure with on-premises servers and cloud-based virtual machines. The client insists on testing only the on-premises systems due to budget constraints. Which of the following should the penetration tester emphasize during the scoping discussion?

⚠ Common exam trap

Many candidates assume budget constraints justify limiting scope to on-premises, but the exam tests the principle that a penetration test must cover the entire attack surface to be valid, and cloud systems are a critical part of that surface in hybrid architectures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Limiting the scope to on-premises may result in an incomplete risk picture because cloud systems are part of the attack surface.

The client's hybrid infrastructure means that cloud-based virtual machines are part of the overall attack surface, and limiting the scope to on-premises systems ignores potential attack vectors such as misconfigured cloud APIs, insecure inter-VPC routing, or compromised cloud credentials that could lead to lateral movement into on-premises systems. A penetration test must assess all components that can be exploited to provide a complete risk picture, as cloud systems often serve as entry points or pivot points into the on-premises environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The on-premises systems are more critical, so testing them is sufficient.

    Why it's wrong here

    Assigning criticality solely by deployment model is an unexamined assumption; cloud workloads often contain sensitive data, support core business functions, and are directly reachable from the internet. Limiting the test to on-premises systems leaves cloud misconfigurations, exposed storage, and weak identity controls unexamined, and attackers commonly pivot from a cloud foothold into the internal network. A scope must be driven by the actual attack surface and data risk, not by a preconceived notion that one environment is inherently more critical.

  • Cloud systems are generally more secure and do not require testing.

    Why it's wrong here

    The shared responsibility model does not make cloud systems secure by default: the provider secures the underlying infrastructure, but the customer is accountable for workload configurations, IAM policies, data encryption, and application-level controls. Misconfigured cloud resources—such as publicly readable storage buckets, over-permissioned roles, or exposed APIs—are frequent entry points in real-world breaches. Assuming cloud systems are inherently more secure ignores these customer-controlled vulnerabilities and can lead to a dangerously incomplete assessment.

  • Limiting the scope to on-premises may result in an incomplete risk picture because cloud systems are part of the attack surface.

    Why this is correct

    A penetration test is meant to evaluate the organization's complete attack surface, which now typically spans both on-premises and cloud-hosted assets, identities, and data. Restricting scope to on-premises creates blind spots for cloud misconfigurations and exposed services that an attacker could exploit to gain an initial foothold, then pivot into the internal environment. Omitting cloud systems from the assessment yields a risk picture that misses significant exposure and cannot accurately reflect the real-world adversarial paths.

  • Testing cloud systems would violate the shared responsibility model.

    Why it's wrong here

    Cloud penetration testing is fully compatible with the shared responsibility model when performed with proper authorization and in line with the provider's testing policies. Providers are responsible for the multi-tenant infrastructure, while customers are responsible for testing the workloads, configurations, applications, and identities they control within the cloud. Violations occur only when testers target the provider's underlying infrastructure without permission, not when they test customer-owned cloud assets, which is both allowed and a standard practice.

About these practice questions

This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.