mediumMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration testing firm is scoping a test for…
A penetration testing firm is scoping a test for a client that uses a hybrid infrastructure with both on-premises servers and cloud-based services (IaaS). The client specifies that only the cloud environment should be tested this year. Which concept is MOST important for the tester to discuss during the scoping meeting to avoid testing out-of-scope assets?
⚠ Common exam trap
The trap here is that candidates may focus on technical testing concerns like false positives or scope expansion, rather than recognizing that the shared responsibility model is the foundational scoping concept that prevents testing the cloud provider's infrastructure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The shared responsibility model between the client and the cloud provider
The shared responsibility model defines which security controls and operational tasks are managed by the cloud provider versus the client. In a scoping meeting, understanding this model is critical because the penetration tester must only target the client's side of the responsibility boundary (e.g., guest OS, applications, and IaaS configurations) and avoid testing the provider's underlying infrastructure, which is out-of-scope. Without this discussion, the tester could inadvertently probe the provider's hypervisor or physical network, violating the scope agreement and potentially causing legal or contractual issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The shared responsibility model between the client and the cloud provider
Why this is correct
The shared responsibility model defines the exact line between provider-managed infrastructure (physical hosts, hypervisor, network fabric) and client-controlled configurations (identity policies, data, application setup). Scoping must map the test exclusively to the client's side of that boundary—for example, testing IAM roles, S3 bucket policies, and security-group rules—while explicitly excluding provider components unless written authorization is obtained. Defining that boundary first prevents wasted effort, avoids accidental disruption of managed services, and keeps the engagement legally and contractually safe.
- ✗
The need to test on-premises systems as well to get a complete picture
Why it's wrong here
Testing on-premises systems would indeed give a more complete security picture, but the client explicitly restricted this engagement to cloud environments, and penetration test scope is defined by the client's authorization, not by the tester's desire for thoroughness. Expanding to on-premises assets would require a separate statement of work, new legal permissions, and different network access, making it a distinct project rather than a scoping adjustment. The immediate scoping question is which cloud assets are in the client's responsibility area, not which hybrid-environment systems could also be tested.
- ✗
The potential for false positives in cloud vulnerability scanners
Why it's wrong here
Cloud vulnerability scanners can produce false positives because managed services commonly patch underlying components automatically or return version fingerprints that differ from the actual service version, but that is a validation and reporting consideration, not a scope-boundary definition. False positives affect how the tester filters and confirms findings during the analysis phase, determine whether an S3 bucket or Lambda function is in scope is decided by the client's requirements and the shared responsibility model. The scanner's error rate does not influence which cloud components are authorized for testing, so it is a secondary operational concern.
- ✗
The cost of third-party cloud penetration testing tools
Why it's wrong here
The cost of third-party cloud penetration testing tools is a budget factor that influences which software the tester selects, but it does not set the logical or technical boundaries of the engagement. Scoping decisions—such as which storage services, API endpoints, or IAM stacks are included—are dictated by the client's objectives and the shared responsibility model, regardless of whether the tester uses an open-source utility or a commercial suite. A tight budget might push a tester toward native provider tools like AWS Inspector or Azure Defender, but that never redefines which assets are in or out of scope.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.