mediumMultiple Select
PT0-002 Practice Question: Before starting a penetration test, the tester…
Before starting a penetration test, the tester receives permission to test only two public IP ranges and is told not to perform denial-of-service testing. Which two documents or artefacts are most important to confirm before testing begins? (Choose 2.)
⚠ Common exam trap
The trap here is that candidates may mistakenly prioritize technical artefacts like exploit lists or screenshots over the legal and scoping documents that are mandatory before any testing begins, confusing operational tools with authorization requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Written authorization to test the specified targets.
Written authorization (A) is the foundational legal document that explicitly grants the tester permission to test the specified public IP ranges, protecting against claims of unauthorized access under laws like the Computer Fraud and Abuse Act. The rules of engagement (B) define the scope boundaries, including the prohibition of denial-of-service testing, which is critical to avoid service disruption and legal liability. Without these two documents, the tester lacks both legal authority and operational constraints, making them the most important artefacts before testing begins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Written authorization to test the specified targets.
Why this is correct
Written authorization to test specified targets is the foundational legal document for any penetration test. It establishes explicit permission from the system owner, defines the exact scope of systems and networks in scope, and limits the tester's authority to those targets. Without this signed authorization, even benign security testing could constitute unauthorized access under laws like the CFAA or similar cybercrime statutes, exposing the tester to civil and criminal liability.
- ✓
Rules of engagement describing prohibited techniques such as DoS.
Why this is correct
Rules of engagement (RoE) are an operational contract that complements the authorization by detailing how the test may be performed, such as allowed testing hours, specific techniques, and emergency stop conditions. Prohibiting techniques like denial-of-service (DoS) is typical because such actions can disrupt production services and cause collateral damage beyond the test's scope. RoE also identifies key contacts, data-handling requirements, and escalation paths, ensuring the test runs within agreed boundaries.
- ✗
A list of exploit payloads from a public GitHub repository.
Why it's wrong here
A list of exploit payloads from a public GitHub repository is merely a collection of code or proof-of-concept exploits, which does not grant any legal right to use them against a target. Possession of hacking tools is not authorization; using them without explicit permission is still illegal, and the payloads may not even be compatible with the target's environment. This artifact is irrelevant to the legal and contractual prerequisites that must be in place before testing begins.
- ✗
A screenshot of the company home page.
Why it's wrong here
A screenshot of the company home page is a piece of publicly available information that could be useful for reconnaissance or OSINT, but it does not define the testing scope or provide any legal authorization. It contains no signatures, target IP addresses, or contractual details, and cannot distinguish allowed systems from out-of-scope assets. As a non-authorizing artifact, it has no bearing on the tester's legal standing or the rules under which the penetration test may proceed.
Go deeper
Related to this question
Learn chapter
Python for Penetration Testing
Key term
Liability
Liability in IT refers to the legal and financial responsibility an organization or individual bears for data breaches, security failures, or compliance violations arising from inadequate planning and scoping of systems and processes.
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.