easyMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration testing firm is scoping a test for…
A penetration testing firm is scoping a test for a client that has a hybrid infrastructure with on-premises servers and cloud-based virtual machines. The client insists on testing only the on-premises systems due to budget constraints. Which of the following should the penetration tester emphasize during the scoping discussion?
⚠ Common exam trap
Many candidates assume budget constraints justify limiting scope to on-premises, but the exam tests the principle that a penetration test must cover the entire attack surface to be valid, and cloud systems are a critical part of that surface in hybrid architectures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Limiting the scope to on-premises may result in an incomplete risk picture because cloud systems are part of the attack surface.
The client's hybrid infrastructure means that cloud-based virtual machines are part of the overall attack surface, and limiting the scope to on-premises systems ignores potential attack vectors such as misconfigured cloud APIs, insecure inter-VPC routing, or compromised cloud credentials that could lead to lateral movement into on-premises systems. A penetration test must assess all components that can be exploited to provide a complete risk picture, as cloud systems often serve as entry points or pivot points into the on-premises environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The on-premises systems are more critical, so testing them is sufficient.
Why it's wrong here
Assigning criticality solely by deployment model is an unexamined assumption; cloud workloads often contain sensitive data, support core business functions, and are directly reachable from the internet. Limiting the test to on-premises systems leaves cloud misconfigurations, exposed storage, and weak identity controls unexamined, and attackers commonly pivot from a cloud foothold into the internal network. A scope must be driven by the actual attack surface and data risk, not by a preconceived notion that one environment is inherently more critical.
- ✗
Cloud systems are generally more secure and do not require testing.
Why it's wrong here
The shared responsibility model does not make cloud systems secure by default: the provider secures the underlying infrastructure, but the customer is accountable for workload configurations, IAM policies, data encryption, and application-level controls. Misconfigured cloud resources—such as publicly readable storage buckets, over-permissioned roles, or exposed APIs—are frequent entry points in real-world breaches. Assuming cloud systems are inherently more secure ignores these customer-controlled vulnerabilities and can lead to a dangerously incomplete assessment.
- ✓
Limiting the scope to on-premises may result in an incomplete risk picture because cloud systems are part of the attack surface.
Why this is correct
A penetration test is meant to evaluate the organization's complete attack surface, which now typically spans both on-premises and cloud-hosted assets, identities, and data. Restricting scope to on-premises creates blind spots for cloud misconfigurations and exposed services that an attacker could exploit to gain an initial foothold, then pivot into the internal environment. Omitting cloud systems from the assessment yields a risk picture that misses significant exposure and cannot accurately reflect the real-world adversarial paths.
- ✗
Testing cloud systems would violate the shared responsibility model.
Why it's wrong here
Cloud penetration testing is fully compatible with the shared responsibility model when performed with proper authorization and in line with the provider's testing policies. Providers are responsible for the multi-tenant infrastructure, while customers are responsible for testing the workloads, configurations, applications, and identities they control within the cloud. Violations occur only when testers target the provider's underlying infrastructure without permission, not when they test customer-owned cloud assets, which is both allowed and a standard practice.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
About these practice questions
This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.