mediumMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration testing firm is scoping a test for…
A penetration testing firm is scoping a test for a financial institution. The client insists that the test only be performed on systems located in the corporate headquarters, excluding cloud-based infrastructure and remote branch offices. Which of the following should the penetration tester emphasize during the scoping discussion?
⚠ Common exam trap
The trap here is that candidates may focus on operational details like timing or social engineering, rather than recognizing that scope exclusions (especially cloud) directly undermine the test's ability to assess the full attack surface, which is a core principle of scoping in PT0-002.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The exclusion of cloud infrastructure may leave critical assets untested
The client's exclusion of cloud-based infrastructure and remote branch offices creates a significant gap in the test scope. A penetration test that ignores cloud assets (e.g., AWS, Azure, or SaaS applications) may miss critical vulnerabilities in systems that process or store sensitive financial data, as these are often part of the institution's attack surface. The tester must emphasize that such exclusions can lead to a false sense of security, as attackers frequently target cloud and remote assets due to their accessibility and potential misconfigurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The test will include social engineering of remote employees
Why it's wrong here
Social engineering is an attack vector, not a network-infrastructure scope item. This scope statement explicitly excludes cloud and branch infrastructure, so the tester's activities would focus on allowed on-premises systems and network segments—not on manipulating remote employees. Adding social engineering would be a separate, clearly authorized objective that the client would have to approve in the SOW; without that, assuming it is included is unwarranted and distracts from the actual scope gap.
- ✓
The exclusion of cloud infrastructure may leave critical assets untested
Why this is correct
The exclusion of cloud and branch infrastructure creates a known blind spot: these environments frequently host financial applications, customer data, or authentication gateways that are critical to the organization's security posture. By declaring them out of scope, the penetration test cannot validate their resilience, leaving the client with a false sense of assurance. This is the core risk of the scope limitation, so emphasizing the impact on the overall security assessment is technically and commercially appropriate.
- ✗
The test can only be performed during off-hours
Why it's wrong here
Off-hours testing is an operational constraint typically driven by availability requirements, not by the scope's infrastructure exclusions. The decision to exclude cloud and branch systems has no direct implication on the time of day the test must run; a test could be performed during business hours or off-hours regardless of those exclusions. Claiming that the exclusion mandates off-hours work confuses scheduling choices with scope coverage, which is a distinct concern.
- ✗
The tester will require VPN access to the corporate network
Why it's wrong here
VPN access is simply a technical enabler for the tester to reach the in-scope corporate network; it says nothing about whether the excluded cloud and branch systems are covered. Even if the tester has full VPN connectivity, the scope statement still prohibits any testing or enumeration of the cloud and branch infrastructure. Thus, VPN access would not mitigate the security risk left by those untested assets, making this statement a distraction from the real scope-coverage problem.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.