PT0-002 Engagement Management Practice Question
During a social engineering engagement, a tester is authorized to target employees via email phishing. However, the tester accidentally sends a phishing email to a contractor who is not listed in the personnel scope. The contractor reports the email to the client's security team, causing an internal investigation. Which of the following best describes the tester's mistake?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Failure to follow the Rules of Engagement
Personnel scope must be clearly defined; the tester failed to adhere to the scoping requirements for social engineering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Breach of the Non-Disclosure Agreement
Why it's wrong here
An NDA is a confidentiality contract that bars the tester from disclosing the client's proprietary or sensitive information. Sending phishing emails to individuals not listed in the engagement scope involves no disclosure of client data, so the NDA is not implicated. The NDA governs post-engagement secrecy, not the operational boundaries of the test.
- ✓
Failure to follow the Rules of Engagement
Why this is correct
The Rules of Engagement (RoE) explicitly define the authorized targets, including personnel, systems, and timeframes, and any deviation from those parameters is a scope violation. By directing phishing emails to out-of-scope individuals, the tester exceeded the documented authorization, which is precisely a failure to follow the RoE. This can invalidate the engagement's legal cover and expose the client or tester to liability.
- ✗
Mishandling of discovered criminal activity
Why it's wrong here
Mishandling criminal activity would require the tester to actually discover evidence of a crime, such as illegal content or fraud, and then fail to report it according to the engagement's incident-handling procedures. In this scenario, the tester only sent phishing messages to unintended recipients; no criminal evidence was discovered. Thus, the issue is not a reporting failure but an authorization failure.
- ✗
Violation of the Computer Fraud and Abuse Act (CFAA)
Why it's wrong here
The CFAA is a criminal statute that prohibits intentionally accessing a computer without authorization or exceeding authorized access. Sending a phishing email to an out-of-scope person does not involve accessing any protected computer, let alone without authorization. The tester's conduct is an operational scope breach, not a technical intrusion, so the CFAA is not the applicable legal or contractual failure.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.