Courseiva
easyMultiple Choice

PT0-002 Practice Question: A small business hires a penetration tester to…

A small business hires a penetration tester to assess the security of their network. The owner is concerned about employee data breaches and wants to ensure compliance with industry regulations. Which of the following is the MOST critical document to establish before the test begins?

⚠ Common exam trap

Watch out — candidates often confuse the Rules of Engagement with the penetration test report or vulnerability scan report, thinking that technical outputs are more important than the legal and scoping document that authorizes the entire test.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rules of engagement

The Rules of Engagement (RoE) is the most critical document because it defines the legal boundaries, scope, and authorization for the penetration test. Without a signed RoE, the tester has no legal protection and the test could be considered unauthorized access, violating laws like the Computer Fraud and Abuse Act (CFAA). It also specifies key constraints such as testing times, target IP ranges, and prohibited actions, ensuring compliance with industry regulations like PCI DSS or HIPAA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vulnerability scan report

    Why it's wrong here

    A vulnerability scan report is a post-engagement artifact produced by automated tools like Nessus or OpenVAS, listing discovered vulnerabilities and their severity scores. It is generated after scanning has begun, not before, and it cannot grant authorization or define what systems may be tested. Therefore, it is not a pre-engagement document that any tester would need before conducting an assessment.

  • ✓

    Rules of engagement

    Why this is correct

    The Rules of Engagement (RoE) is the core pre-engagement document that formalizes the client's authorization, defining the exact scope of target systems, allowed testing windows, permissible exploitation techniques, and emergency contact procedures. It serves as a legal safeguard for both the tester and the client, ensuring that all activity is explicitly sanctioned and that any deviation from the agreed terms is documented. Without a signed RoE, any penetration testing activity would be considered unauthorized access, exposing both parties to legal liability.

  • ✗

    Penetration test report

    Why it's wrong here

    A penetration test report is the final deliverable that synthesizes the tester's findings, including exploited vulnerabilities, evidence of impact, and prioritized remediation recommendations. It is inherently produced after the conclusion of testing, meaning it cannot exist prior to the engagement to authorize or constrain the work. Confusing this output with a pre-engagement document would be a logical fallacy, as the report's content depends entirely on the test results that have not yet occurred.

  • ✗

    Risk assessment matrix

    Why it's wrong here

    A risk assessment matrix is a qualitative tool used to categorize threats by likelihood and impact, often consulted during scoping discussions to prioritize which assets need testing. While it can inform the scope and highlight high-risk areas, it is not a binding legal agreement and provides no explicit authorization for active exploitation or intrusive testing. The RoE is the document that takes this risk information and converts it into an enforceable, signed authorization with clear boundaries.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.