mediumMultiple Choice
PT0-002 Practice Question: During a penetration test, a client asks the…
During a penetration test, a client asks the tester to clarify the scope of the test. Which of the following is the best approach for the tester?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Clarify with the client via email or documented communication.
Clarifying scope questions helps ensure the test stays within agreed boundaries and avoids misunderstandings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Make a decision based on previous tests.
Why it's wrong here
Relying on previous tests is unsound because each penetration test is governed by a unique rules-of-engagement (ROE) document, contractual scope, and authorized asset list. Network architectures, threat models, and even client decision-makers change over time, so assumptions from an older engagement may include systems that are now out-of-bounds or exclude newly critical targets. The tester must treat the current engagement's scope as the sole source of truth and obtain explicit written clarification rather than extrapolating from stale data.
- ✓
Clarify with the client via email or documented communication.
Why this is correct
Clarifying via email or documented communication is the correct action because it creates an auditable trail of the scope decision, which is essential for legal and compliance purposes. The written confirmation should specify the exact IP ranges, domain names, or testing techniques in question, along with the client's approval, to serve as a formal amendment to the rules of engagement. This approach also protects both parties and ensures that any subsequent testing activities are fully authorized and defensible.
- ✗
Include the scope in the report after testing.
Why it's wrong here
Documenting the scope only in the final report is an after-the-fact rationalization that cannot retroactively authorize testing activities. If the tester proceeds without clarity, any actions taken may exceed the approved boundaries, potentially violating the Computer Fraud and Abuse Act or equivalent laws and the client's own security policies. Scope decisions must be locked down before exploitation or intrusive testing begins, because the report should reflect what was authorized, not attempt to justify what was not.
- ✗
Ignore the question and continue testing.
Why it's wrong here
Ignoring the ambiguity and continuing to test risks a scope breach, which could cause unintended disruption to systems, legal exposure for the tester, and reputational damage to the client. Unauthorized testing may also trigger security controls or incident response procedures, causing alert fatigue and poisoning the data. The ethically and legally sound move is to pause, request written clarification, and wait for approval before proceeding with any further intrusive actions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.