Courseiva
hardMultiple Choice

PT0-002 Practice Question: During a penetration test for a financial…

During a penetration test for a financial institution, the tester discovers that a third-party vendor's system is vulnerable and could expose customer PII. The tester is unsure if the vendor is within scope. How should the tester proceed?

⚠ Common exam trap

PT0-003 often tests the misconception that confirming a vulnerability justifies out-of-scope testing, when the correct action is always to clarify scope with the client before proceeding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Communicate with the client to clarify whether the vendor is in scope

When a penetration tester discovers a vulnerability on a system whose scope status is unclear, the correct professional and ethical action is to stop and clarify scope with the client before doing anything else. Testing an out-of-scope third-party vendor system without authorization could be illegal and violate the rules of engagement. Communicating with the client to confirm scope is the safe, compliant step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform additional testing on the vendor system to confirm the vulnerability

    Why it's wrong here

    Testing the vendor system without authorisation exceeds the agreed scope and may be illegal, regardless of confirming the vulnerability. It is tempting because validating a finding before reporting reduces false positives, and additional testing is correct when the system is confirmed in scope — but scope uncertainty must be resolved with the client first.

  • ✗

    Ignore the finding since it is out of scope

    Why it's wrong here

    Ignoring the finding leaves exposed customer PII unaddressed and breaches the tester's duty to report discovered risk. It is tempting because staying strictly within scope avoids legal exposure, and ignoring out-of-scope systems is defensible when no sensitive data is implicated — but here the PII exposure demands escalation to the client for scope clarification.

  • ✗

    Include the vulnerability in the final report as a high-risk finding

    Why it's wrong here

    Reporting it as a confirmed high-risk finding asserts an impact and scope the tester has not verified, potentially misrepresenting results. It is tempting because documenting all observations protects the client, and reporting is correct once scope and severity are established — but the finding should be flagged as unverified pending client clarification.

  • ✓

    Communicate with the client to clarify whether the vendor is in scope

    Why this is correct

    Scope is defined solely by the client's authorisation. Testing a third-party vendor without confirmed permission risks legal exposure, so the tester must pause and obtain written clarification from the client before touching the vendor's system.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.