Courseiva
easyMultiple ChoiceObjective-mapped

PT0-002 Practice Question: A client wants to conduct a penetration test of…

A client wants to conduct a penetration test of their e-commerce website. They are concerned about impacting live transactions. Which clause should be included in the Rules of Engagement to address this?

⚠ Common exam trap

Watch out — candidates often confuse 'out-of-scope systems' with operational restrictions, failing to realize that even in-scope systems can be disrupted by stress testing, so a specific exclusion clause is required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Exclusion of network stress testing and availability testing.

The client's primary concern is avoiding disruption to live transactions. A clause excluding network stress testing and availability testing (e.g., DoS attacks, resource exhaustion, or high-volume scanning) directly addresses this by prohibiting any action that could degrade performance or cause downtime. This is a standard Rules of Engagement (RoE) safeguard for production e-commerce environments where transaction integrity and uptime are critical.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Exclusion of network stress testing and availability testing.

    Why this is correct

    An exclusion of network stress testing and availability testing directly protects the live e-commerce infrastructure by prohibiting load simulation, distributed denial-of-service (DDoS) emulation, resource-exhaustion attempts, and any technique designed to consume bandwidth, CPU, memory, or connection state. This clause constrains the testing methodology itself, ensuring the tester still can evaluate injection flaws, auth issues, and business logic while leaving transactional capacity unscathed. It is the only option that specifically addresses the client's concern about service impact rather than merely defining targets.

  • Out-of-scope systems list.

    Why it's wrong here

    An out-of-scope systems list tells the tester which hosts, networks, or services cannot be touched, such as the inventory backend or internal admin portal. However, it does not restrict the testing posture or intensity; the tester could run aggressive fuzzing, high-rate login brute forcing, or a fast web crawler solely against the in-scope site and still induce server degradation or a crash. This clause is valuable for protecting adjacent infrastructure but cannot guarantee that the live site itself remains available.

  • In-scope IP addresses.

    Why it's wrong here

    In-scope IP addresses simply enumerate the authorized targets, for example 203.0.113.10/32 for the public storefront, but they place no limitation on test methods. Unthrottled port scanning, mass parameter fuzzing, or concurrent request floods aimed at those IPs can saturate the web tier and cause connection timeouts for real shoppers. While this scope definition is essential for authorization, it leaves the client's availability requirement unmet because it fails to constrain test-generated load on the production host.

  • Authorization for testing.

    Why it's wrong here

    Authorization for testing provides the legal and contractual permission needed to launch reconnaissance and exploit attempts against the client's assets, but it does not by itself impose technical safety limits. A fully authorized tester could still misjudge the impact of a chosen exploit or fail to throttle a verification script, thereby triggering cascading failures in a microservices architecture and taking the store offline. Proper authorization is a prerequisite, yet without an explicit clause limiting disruptive techniques, it does nothing to mitigate the specific risk the client described.

About these practice questions

One of 185 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.