Courseiva

PT0-003 · domain

Engagement Management

Engagement Management covers the pre- and post-engagement paperwork and conduct that frame a penetration test: scoping, rules of engagement, authorization, legal boundaries, and evidence handling. PT0-003 tests this through scenario questions about multi-tenant cloud scope, get-out-of-jail letters, discovering criminal activity, and proper data handling and retention after the report is delivered.

62 questions17 easy30 medium15 hard

Focused practice

Practice Engagement Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Engagement Management

Be able to read a scenario and identify the correct authorization, scoping, and post-engagement data-handling actions. The single most important thing: no testing without explicit, signed, scope-specific authorization, and no client data retained beyond agreed terms.

Rules of engagement defining authorized targets, time windows, testing methods, and emergency contacts before any scanning begins

Get-out-of-jail letter (authorization to test) naming the client, scope, dates, and authorizing signatory to prove permission

Scoping multi-tenant cloud and shared-hosting environments to avoid testing systems outside the client's control or ownership

Post-engagement data handling: secure destruction or return of collected client data, credentials, and evidence per contract terms

Watch out for

Common Engagement Management exam traps

  • ▸Treating a get-out-of-jail letter as optional or generic instead of scope-specific, dated, and signed by someone with authority to authorize testing
  • ▸Testing adjacent tenants or shared infrastructure on a cloud platform because it is reachable, exceeding the authorized scope
  • ▸Keeping client data, credentials, or evidence indefinitely after engagement close instead of following agreed retention and destruction terms

Question index

All Engagement Management questions (62)

Click any question to see the full explanation, or start a practice session above.

1

A penetration tester is planning a social engineering engagement targeting employees of a client. The client requests that only non-managerial staff be tested. Which scoping consideration is most directly affected by this request?

Medium
2

During a social engineering engagement, a tester is authorized to target employees via email phishing. However, the tester accidentally sends a phishing email to a contractor who is not listed in the personnel scope. The contractor reports the email to the client's security team, causing an internal investigation. Which of the following best describes the tester's mistake?

Hard
3

Which of the following is the primary purpose of a get-out-of-jail letter in a penetration testing engagement?

Medium
4

A penetration testing company is scoping a test for a client. The client wants to ensure that testing does not impact production systems. Which TWO of the following are appropriate scoping considerations? (Select TWO.)

Medium
5

During the pre-engagement phase, a penetration tester and the client agree on the specific IP ranges to be tested, testing windows, and what constitutes an emergency stop condition. Which document typically contains these details?

Medium
6

A company hires a penetration testing firm to simulate the tactics, techniques, and procedures of a real adversary. The engagement includes attempting to achieve specific objectives without being detected. This type of engagement is best described as:

Easy
7

A penetration tester is scoping a web application penetration test. The client wants to include a third-party API that processes payments. Which TWO are appropriate considerations?

Medium
8

A penetration tester is conducting a grey box test on a web application. During the test, the tester discovers that the application is hosted on a cloud infrastructure that belongs to a third-party provider. The client did not mention this provider in the scope. What is the best course of action regarding testing this infrastructure?

Hard
9

A company wants to simulate a real-world attack scenario where the penetration tester has no prior knowledge of the environment and must act as an external threat actor. However, the tester is allowed to use social engineering to gain initial access. Which type of engagement is most appropriate?

Medium
10

Which penetration testing standard provides a structured methodology for conducting penetration tests, including pre-engagement, reconnaissance, and reporting phases?

Easy
11

A penetration tester is performing a wireless penetration test. The RoE states that testing is only allowed between 8 PM and 6 AM. At 7:30 PM, the tester begins active scanning. At 8:15 PM, a client employee calls emergency contact to report suspicious activity. According to the RoE, which of the following is the most likely reason for the call?

Hard
12

During an external penetration test, the tester discovers that a critical web application is hosted on a third-party cloud provider. The SOW did not mention this provider. What should the tester do before proceeding with testing against that provider's infrastructure?

Medium
13

Which of the following is typically included in the final deliverables of a penetration test?

Medium
14

A penetration tester is scoping a network penetration test for a client that uses multiple third-party services. Which TWO of the following are correct actions regarding third-party services? (Select TWO.)

Medium
15

During a penetration test, the tester discovers evidence of an ongoing criminal activity, such as unauthorized data exfiltration by an insider. The client's legal team has not provided specific guidance on handling such discoveries. According to best practices and legal considerations, what should the tester do first?

Hard
16

During post-engagement, a penetration tester needs to ensure proper data handling. Which THREE actions should the tester take?

Hard
17

A penetration tester discovers evidence of ongoing criminal activity, such as a data breach by an internal employee, during a white box penetration test. The client's legal team has not provided specific instructions on handling such discoveries. According to best practices and legal considerations, what should the tester do first?

Hard
18

A penetration tester is hired to assess the security of a company's internal network. The tester is given full network diagrams, credentials, and source code. Which type of penetration test is being performed?

Easy
19

A penetration testing company is contracted to perform a social engineering engagement. The client requests that only employees in the finance department be targeted. Which scoping consideration is most relevant?

Medium
20

During a pre-engagement meeting, the client states that no testing is allowed on the wireless network or on any cloud-based services hosted by third parties. Which part of the engagement documentation would specify these restrictions?

Medium
21

A penetration tester is conducting a red team exercise. The goal is to simulate an advanced persistent threat (APT) and test the organization's detection and response capabilities. Which of the following engagement types best describes this scenario?

Medium
22

A penetration tester is preparing for a web application penetration test. The client application is hosted on a cloud platform that serves multiple tenants. Which THREE of the following are critical legal and scoping considerations?

Hard
23

Which of the following is the primary purpose of a get-out-of-jail letter?

Easy
24

A penetration tester is engaged to test a web application that uses a third-party payment gateway. The client has not obtained permission from the payment gateway provider. Which of the following is the best course of action?

Hard
25

The penetration tester identifies that a web application is hosted on a server that also contains sensitive customer data unrelated to the test. The SOW clearly states that only the web application is in scope. The tester accidentally accesses the customer data. What should the tester do immediately?

Medium
26

A penetration tester is planning a red team exercise for a client. The client insists that the testing should not disrupt production systems and only target a replicated staging environment. However, the tester believes that testing the production environment is necessary for realistic adversary simulation. What is the MOST appropriate course of action?

Medium
27

During pre-engagement, a client insists that the penetration testers sign a non-disclosure agreement (NDA). However, the client refuses to provide a 'get-out-of-jail' letter. What risk does this pose to the penetration testers?

Medium
28

Which TWO of the following are typical deliverables of a penetration test?

Easy
29

Which TWO of the following are types of penetration testing based on the level of knowledge provided to the tester? (Select TWO.)

Easy
30

Which type of penetration test provides the tester with full knowledge of the target environment, including network diagrams, source code, and administrative credentials?

Easy
31

Which penetration testing standard provides a step-by-step methodology from pre-engagement through post-engagement activities, including intelligence gathering, vulnerability analysis, and exploitation?

Easy
32

Which legal framework in the United States prohibits unauthorized access to computer systems and is commonly referenced in penetration testing authorization documents?

Medium
33

A penetration tester is contracted to perform a grey box test of a company's internal network. The client provides a VPN account for remote access but does not disclose that the account has been used by a former employee. The tester connects and is immediately locked out. Which pre-engagement document should have addressed this scenario?

Hard
34

A penetration testing engagement requires testing a production environment during business hours. The client is concerned about potential service disruption. Which document should specify the conditions under which the test must be halted?

Medium
35

During a penetration test, the tester discovers evidence of an ongoing data breach that appears to involve criminal activity unrelated to the test scope. What is the tester's primary responsibility regarding this discovery?

Medium
36

A penetration tester is conducting a wireless network assessment for a client. The client has provided a list of authorized SSIDs and MAC addresses of access points. During the assessment, the tester discovers a rogue access point that is not on the authorized list and is broadcasting a similar SSID to the corporate network. Which TWO of the following actions should the tester take? (Choose two.)

Hard
37

A penetration tester is hired to perform an assessment where the tester is provided with network diagrams, source code, and administrative credentials. Which type of penetration test is this?

Easy
38

During the pre-engagement phase, which document defines the IP ranges, test windows, and emergency stop criteria for a penetration test?

Easy
39

A penetration tester is planning a web application test. The client wants to minimize risk to production data. Which environment should the tester recommend for testing?

Medium
40

A penetration tester is preparing a deliverable for a client. Which of the following should be included in the final report?

Easy
41

A penetration testing firm is scoping a network penetration test for a client. The client has provided a list of IP ranges and subnets. Which TWO of the following should the tester consider when defining the scope?

Medium
42

Which THREE of the following are common components of a pre-engagement agreement between a penetration tester and a client?

Easy
43

Which penetration testing standard provides a methodology that includes pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting?

Easy
44

A penetration tester is hired to assess the security of a company's internal network. The client provides the tester with full network diagrams, credentials, and source code. Which type of penetration test is being performed?

Easy
45

A penetration tester is about to start an engagement. Which document outlines the IP ranges that are in scope, the testing window, and the emergency stop criteria?

Medium
46

After completing a penetration test, the tester must deliver a report. According to standard practices, which of the following is a required component of the deliverables?

Medium
47

A penetration tester is preparing for a social engineering engagement. The client has requested that the tester attempt to gain access to the building by impersonating a delivery person. Which of the following should the tester obtain from the client before conducting the test?

Easy
48

A penetration tester is preparing a proposal for a client. The client wants a test that includes a detailed technical report with remediation steps and an executive summary for management. Which standard or framework is most commonly used to structure the testing process from pre-engagement through post-engagement?

Medium
49

A company is planning a social engineering engagement. Which TWO items should be included in the pre-engagement documentation?

Easy
50

A penetration testing company is planning a social engineering engagement for a client. The engagement includes phishing and physical tailgating. Which THREE of the following should be clearly defined in the Rules of Engagement? (Select THREE.)

Hard
51

A client requests a penetration test that includes testing of both internal network devices and a public-facing web application. The tester is provided with a VPN account for internal access but no credentials for the web application. Which type of penetration test is this?

Medium
52

In a red team exercise, the team wants to simulate a realistic adversary. Which TWO of the following are typically included in the scope of a red team engagement compared to a standard penetration test?

Medium
53

A penetration tester discovers evidence of an ongoing criminal activity (e.g., data exfiltration by an insider) during a test. According to best practices and legal considerations, which THREE actions should the tester take?

Hard
54

A penetration tester is scoping a test for a client that uses a SaaS application for customer relationship management. The client wants the tester to assess the application's security. What is the most important consideration regarding this SaaS application?

Hard
55

A penetration tester is conducting a red team engagement for a financial institution. The client has requested that the tester simulate a ransomware attack to test the incident response process. During the test, the tester encrypts a file share containing simulated customer data. The client's security team detects the encryption and initiates their incident response plan. Which of the following should the tester do FIRST to ensure the engagement remains within scope and does not cause operational disruption?

Hard
56

After completing a penetration test, the tester must handle test artifacts appropriately. Which TWO of the following are best practices for data handling and destruction?

Medium
57

A penetration tester is conducting a wireless penetration test. The client's rules of engagement state that testing must not disrupt production services. During the test, the tester's de-authentication attack causes the company's guest Wi-Fi to go offline. What should the tester do?

Hard
58

Which legal framework in the United States makes it a crime to access a computer system without authorization, and is a key consideration when obtaining permission for penetration testing?

Medium
59

Which of the following best describes the purpose of a vulnerability disclosure policy in the context of a penetration test?

Medium
60

A penetration tester is planning a test that involves scanning for vulnerabilities across a large IP range. The client has provided a list of IPs that are in-scope, but the tester notices that some IPs belong to a third-party company hosting a client application. What should the tester do?

Medium
61

Which of the following penetration testing standards includes detailed guidelines for pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting?

Medium
62

A penetration tester is hired to perform a test with no prior knowledge of the target environment. The tester is given only the company name and must gather all necessary information from public sources. Which type of penetration test is this?

Easy

Frequently asked questions

What does the Engagement Management domain cover on the PT0-003 exam?
Be able to read a scenario and identify the correct authorization, scoping, and post-engagement data-handling actions. The single most important thing: no testing without explicit, signed, scope-specific authorization, and no client data retained beyond agreed terms.
How many questions are in this domain?
This page lists all 62 Engagement Management questions in the PT0-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Engagement Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
pentest-plus PENTEST-PLUS ptp planning scoping Practice Questions