Courseiva
mediumMultiple Choice

PT0-002 Practice Question: During a penetration test, a client asks the…

During a penetration test, a client asks the tester to clarify the scope of the test. Which of the following is the best approach for the tester?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Clarify with the client via email or documented communication.

Clarifying scope questions helps ensure the test stays within agreed boundaries and avoids misunderstandings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Make a decision based on previous tests.

    Why it's wrong here

    Relying on previous tests is unsound because each penetration test is governed by a unique rules-of-engagement (ROE) document, contractual scope, and authorized asset list. Network architectures, threat models, and even client decision-makers change over time, so assumptions from an older engagement may include systems that are now out-of-bounds or exclude newly critical targets. The tester must treat the current engagement's scope as the sole source of truth and obtain explicit written clarification rather than extrapolating from stale data.

  • ✓

    Clarify with the client via email or documented communication.

    Why this is correct

    Clarifying via email or documented communication is the correct action because it creates an auditable trail of the scope decision, which is essential for legal and compliance purposes. The written confirmation should specify the exact IP ranges, domain names, or testing techniques in question, along with the client's approval, to serve as a formal amendment to the rules of engagement. This approach also protects both parties and ensures that any subsequent testing activities are fully authorized and defensible.

  • ✗

    Include the scope in the report after testing.

    Why it's wrong here

    Documenting the scope only in the final report is an after-the-fact rationalization that cannot retroactively authorize testing activities. If the tester proceeds without clarity, any actions taken may exceed the approved boundaries, potentially violating the Computer Fraud and Abuse Act or equivalent laws and the client's own security policies. Scope decisions must be locked down before exploitation or intrusive testing begins, because the report should reflect what was authorized, not attempt to justify what was not.

  • ✗

    Ignore the question and continue testing.

    Why it's wrong here

    Ignoring the ambiguity and continuing to test risks a scope breach, which could cause unintended disruption to systems, legal exposure for the tester, and reputational damage to the client. Unauthorized testing may also trigger security controls or incident response procedures, causing alert fatigue and poisoning the data. The ethically and legally sound move is to pause, request written clarification, and wait for approval before proceeding with any further intrusive actions.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.