Courseiva
mediumMultiple ChoiceObjective-mapped

Documenting Scope Exclusions in the Rules of Engagement

A client wants to test a web application that uses a third-party payment gateway. The client explicitly wants the payment gateway to be excluded from the test to avoid service disruption. Where should this exclusion be formally documented?

Quick Answer

The answer is the Rules of Engagement (ROE) document. This is the correct place to formally document scope exclusions in a penetration test because the ROE serves as the binding agreement that defines all boundaries, constraints, and authorized targets for the engagement. When a client explicitly wants a third-party payment gateway excluded to avoid service disruption, that exclusion must be captured in the ROE to ensure it is legally and operationally enforced, preventing testers from inadvertently impacting the system. On the CompTIA PenTest+ PT0-002 exam, this concept tests your understanding of pre-engagement documentation and the distinction between the ROE, which covers legal and operational constraints, and the scope statement, which lists what is in scope. A common trap is confusing the ROE with the test plan or methodology—remember, the ROE is the "rulebook" for what you can and cannot touch. Memory tip: ROE = Rules of Engagement = Restrictions on Everything excluded.

⚠ Common exam trap

Watch out — candidates often confuse the Penetration Test Plan (which details how to test) with the Rules of Engagement (which defines what is allowed and forbidden), leading them to incorrectly select the Plan instead of the ROE for scope exclusions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Rules of Engagement (ROE)

The Rules of Engagement (ROE) document is the correct place to formally exclude the third-party payment gateway from testing. The ROE defines the scope, boundaries, and constraints of the penetration test, including specific systems or services that must not be targeted. This ensures the client's requirement to avoid service disruption to the payment gateway is legally and operationally enforced.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Non-Disclosure Agreement (NDA)

    Why it's wrong here

    The NDA covers confidentiality of findings, not scope exclusions.

  • Statement of Work (SOW)

    Why it's wrong here

    The SOW defines deliverables and timeline but not granular exclusions.

  • Rules of Engagement (ROE)

    Why this is correct

    The ROE documents scope, exclusions, and rules for the test.

  • Penetration Test Plan

    Why it's wrong here

    The test plan details the methodology, but exclusions are typically in the ROE.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on PT0-003

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A client requests a penetration test of their web application, but they want to exclude all third-party APIs from the scope. Where should this exclusion be documented?

easy
  • A.Rules of Engagement
  • B.Executive Summary
  • C.Findings Report
  • D.Remediation Plan

Why A: The Rules of Engagement (ROE) document is the authoritative source for defining the scope, boundaries, and constraints of a penetration test, including explicit exclusions such as third-party APIs. This document is established during the planning and scoping phase to ensure both the client and the testing team agree on what is and is not in scope, preventing legal or operational issues. Without documenting the exclusion in the ROE, the tester might inadvertently interact with the third-party APIs, violating the agreement and potentially causing service disruptions or legal liabilities.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.