hardMultiple Select
PT0-002 Practice Question: During a penetration test, the tester encounters…
During a penetration test, the tester encounters a situation where the scope of the test is ambiguous. Which TWO actions should the tester take to clarify the situation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the ambiguity and the agreed-upon resolution in the test plan.
When scope is unclear, the tester should communicate with the client and document the assumptions to avoid misunderstandings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Document the ambiguity and the agreed-upon resolution in the test plan.
Why this is correct
Documenting the ambiguity and its agreed-upon resolution in the test plan creates an auditable record that prevents disputes over authorization, aligns the engagement with the rules of the contract, and ensures the final report accurately reflects the tested boundaries. This change-control step is essential for legal defensibility and professional accountability.
- ✗
Proceed with the test based on the tester's best guess.
Why it's wrong here
Proceeding on a best guess substitutes personal judgment for explicit client authorization, risking activities against systems not covered by the engagement’s legal and contractual boundaries. Such actions could constitute unauthorized access, expose the tester to liability, and invalidate the penetration test's findings, making the test both legally and technically flawed.
- ✗
Test all systems within the network to ensure thoroughness.
Why it's wrong here
Testing every system within the network reflects a misunderstanding of thoroughness: it is not thorough to exceed the scope but rather to violate it. Expanding beyond the agreed-upon assets may involve production systems or third-party infrastructure, causing outages or legal consequences, and the tester would lack the authority to perform such actions.
- ✗
Ignore the ambiguity and continue testing the original scope.
Why it's wrong here
Ignoring ambiguity and sticking to the original scope leaves unresolved questions that could later reveal you tested the wrong assets or missed critical systems due to misinterpretation. This approach assumes the original scope is unambiguous when it is not, and failing to address the uncertainty can compromise the test’s accuracy and create conflicts with the client.
- ✓
Contact the client to clarify the scope before proceeding.
Why this is correct
Contacting the client to clarify scope before proceeding is correct because it obtains authoritative information directly from the system owner, ensuring the tester operates only within authorized boundaries. However, the tester must follow up by documenting the clarification in the test plan; communication alone does not create the formal record necessary for audit and reporting.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.