Courseiva
mediumMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration testing firm is scoping a test for…

A penetration testing firm is scoping a test for a client that uses a hybrid infrastructure with both on-premises servers and cloud-based services (IaaS). The client specifies that only the cloud environment should be tested this year. Which concept is MOST important for the tester to discuss during the scoping meeting to avoid testing out-of-scope assets?

⚠ Common exam trap

The trap here is that candidates may focus on technical testing concerns like false positives or scope expansion, rather than recognizing that the shared responsibility model is the foundational scoping concept that prevents testing the cloud provider's infrastructure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The shared responsibility model between the client and the cloud provider

The shared responsibility model defines which security controls and operational tasks are managed by the cloud provider versus the client. In a scoping meeting, understanding this model is critical because the penetration tester must only target the client's side of the responsibility boundary (e.g., guest OS, applications, and IaaS configurations) and avoid testing the provider's underlying infrastructure, which is out-of-scope. Without this discussion, the tester could inadvertently probe the provider's hypervisor or physical network, violating the scope agreement and potentially causing legal or contractual issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The shared responsibility model between the client and the cloud provider

    Why this is correct

    The shared responsibility model defines the exact line between provider-managed infrastructure (physical hosts, hypervisor, network fabric) and client-controlled configurations (identity policies, data, application setup). Scoping must map the test exclusively to the client's side of that boundary—for example, testing IAM roles, S3 bucket policies, and security-group rules—while explicitly excluding provider components unless written authorization is obtained. Defining that boundary first prevents wasted effort, avoids accidental disruption of managed services, and keeps the engagement legally and contractually safe.

  • The need to test on-premises systems as well to get a complete picture

    Why it's wrong here

    Testing on-premises systems would indeed give a more complete security picture, but the client explicitly restricted this engagement to cloud environments, and penetration test scope is defined by the client's authorization, not by the tester's desire for thoroughness. Expanding to on-premises assets would require a separate statement of work, new legal permissions, and different network access, making it a distinct project rather than a scoping adjustment. The immediate scoping question is which cloud assets are in the client's responsibility area, not which hybrid-environment systems could also be tested.

  • The potential for false positives in cloud vulnerability scanners

    Why it's wrong here

    Cloud vulnerability scanners can produce false positives because managed services commonly patch underlying components automatically or return version fingerprints that differ from the actual service version, but that is a validation and reporting consideration, not a scope-boundary definition. False positives affect how the tester filters and confirms findings during the analysis phase, determine whether an S3 bucket or Lambda function is in scope is decided by the client's requirements and the shared responsibility model. The scanner's error rate does not influence which cloud components are authorized for testing, so it is a secondary operational concern.

  • The cost of third-party cloud penetration testing tools

    Why it's wrong here

    The cost of third-party cloud penetration testing tools is a budget factor that influences which software the tester selects, but it does not set the logical or technical boundaries of the engagement. Scoping decisions—such as which storage services, API endpoints, or IAM stacks are included—are dictated by the client's objectives and the shared responsibility model, regardless of whether the tester uses an open-source utility or a commercial suite. A tight budget might push a tester toward native provider tools like AWS Inspector or Azure Defender, but that never redefines which assets are in or out of scope.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.