Courseiva
mediumMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A penetration testing firm is scoping a test for…

A penetration testing firm is scoping a test for a financial institution. The client insists that the test only be performed on systems located in the corporate headquarters, excluding cloud-based infrastructure and remote branch offices. Which of the following should the penetration tester emphasize during the scoping discussion?

⚠ Common exam trap

The trap here is that candidates may focus on operational details like timing or social engineering, rather than recognizing that scope exclusions (especially cloud) directly undermine the test's ability to assess the full attack surface, which is a core principle of scoping in PT0-002.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The exclusion of cloud infrastructure may leave critical assets untested

The client's exclusion of cloud-based infrastructure and remote branch offices creates a significant gap in the test scope. A penetration test that ignores cloud assets (e.g., AWS, Azure, or SaaS applications) may miss critical vulnerabilities in systems that process or store sensitive financial data, as these are often part of the institution's attack surface. The tester must emphasize that such exclusions can lead to a false sense of security, as attackers frequently target cloud and remote assets due to their accessibility and potential misconfigurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The test will include social engineering of remote employees

    Why it's wrong here

    Social engineering is an attack vector, not a network-infrastructure scope item. This scope statement explicitly excludes cloud and branch infrastructure, so the tester's activities would focus on allowed on-premises systems and network segments—not on manipulating remote employees. Adding social engineering would be a separate, clearly authorized objective that the client would have to approve in the SOW; without that, assuming it is included is unwarranted and distracts from the actual scope gap.

  • The exclusion of cloud infrastructure may leave critical assets untested

    Why this is correct

    The exclusion of cloud and branch infrastructure creates a known blind spot: these environments frequently host financial applications, customer data, or authentication gateways that are critical to the organization's security posture. By declaring them out of scope, the penetration test cannot validate their resilience, leaving the client with a false sense of assurance. This is the core risk of the scope limitation, so emphasizing the impact on the overall security assessment is technically and commercially appropriate.

  • The test can only be performed during off-hours

    Why it's wrong here

    Off-hours testing is an operational constraint typically driven by availability requirements, not by the scope's infrastructure exclusions. The decision to exclude cloud and branch systems has no direct implication on the time of day the test must run; a test could be performed during business hours or off-hours regardless of those exclusions. Claiming that the exclusion mandates off-hours work confuses scheduling choices with scope coverage, which is a distinct concern.

  • The tester will require VPN access to the corporate network

    Why it's wrong here

    VPN access is simply a technical enabler for the tester to reach the in-scope corporate network; it says nothing about whether the excluded cloud and branch systems are covered. Even if the tester has full VPN connectivity, the scope statement still prohibits any testing or enumeration of the cloud and branch infrastructure. Thus, VPN access would not mitigate the security risk left by those untested assets, making this statement a distraction from the real scope-coverage problem.

About these practice questions

One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.