hardMultiple Choice
PT0-002 Practice Question: During a penetration test for a financial…
During a penetration test for a financial institution, the tester discovers that a third-party vendor's system is vulnerable and could expose customer PII. The tester is unsure if the vendor is within scope. How should the tester proceed?
⚠ Common exam trap
PT0-003 often tests the misconception that confirming a vulnerability justifies out-of-scope testing, when the correct action is always to clarify scope with the client before proceeding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Communicate with the client to clarify whether the vendor is in scope
When a penetration tester discovers a vulnerability on a system whose scope status is unclear, the correct professional and ethical action is to stop and clarify scope with the client before doing anything else. Testing an out-of-scope third-party vendor system without authorization could be illegal and violate the rules of engagement. Communicating with the client to confirm scope is the safe, compliant step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform additional testing on the vendor system to confirm the vulnerability
Why it's wrong here
Testing the vendor system without authorisation exceeds the agreed scope and may be illegal, regardless of confirming the vulnerability. It is tempting because validating a finding before reporting reduces false positives, and additional testing is correct when the system is confirmed in scope — but scope uncertainty must be resolved with the client first.
- ✗
Ignore the finding since it is out of scope
Why it's wrong here
Ignoring the finding leaves exposed customer PII unaddressed and breaches the tester's duty to report discovered risk. It is tempting because staying strictly within scope avoids legal exposure, and ignoring out-of-scope systems is defensible when no sensitive data is implicated — but here the PII exposure demands escalation to the client for scope clarification.
- ✗
Include the vulnerability in the final report as a high-risk finding
Why it's wrong here
Reporting it as a confirmed high-risk finding asserts an impact and scope the tester has not verified, potentially misrepresenting results. It is tempting because documenting all observations protects the client, and reporting is correct once scope and severity are established — but the finding should be flagged as unverified pending client clarification.
- ✓
Communicate with the client to clarify whether the vendor is in scope
Why this is correct
Scope is defined solely by the client's authorisation. Testing a third-party vendor without confirmed permission risks legal exposure, so the tester must pause and obtain written clarification from the client before touching the vendor's system.
Go deeper
Related to this question
Learn chapter
Re-Testing and Validation Testing
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.