PT0-002 Engagement Management Practice Question
During an external penetration test, the tester discovers that a critical web application is hosted on a third-party cloud provider. The SOW did not mention this provider. What should the tester do before proceeding with testing against that provider's infrastructure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtain written authorization from the third-party provider
Testing third-party services requires explicit permission from the provider to avoid legal and contractual issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Obtain written authorization from the third-party provider
Why this is correct
Obtaining written authorization from the third-party provider is mandatory because the provider owns or controls the asset; without their explicit consent, testing constitutes unauthorized access, potentially violating computer fraud laws and civil agreements. This authorization must be documented in the rules of engagement and ideally obtained before any testing begins, as the client's scope alone cannot transfer ownership rights.
- ✗
Scan only the IP addresses that resolve to the client's domain
Why it's wrong here
Scanning only IP addresses that resolve to the client's domain is insufficient because the web application may be hosted on shared infrastructure, a CDN, or a cloud provider where the underlying servers are not owned by the client. Even if the DNS record points to the client's subdomain, the provider retains administrative control, and scanning those IPs without their permission is still unauthorized and may be illegal.
- ✗
Continue testing as long as the target is in scope
Why it's wrong here
Continuing testing solely because the target is in scope is dangerous because scope is defined by the client, but the client cannot grant permission for assets they do not own. Penetration testers must verify that every in-scope asset is either owned by the client or covered by explicit third-party authorization; otherwise, they risk violating the Computer Fraud and Abuse Act or the provider's terms of service, which can lead to legal action and loss of credentials.
- ✗
Ignore the web application and test only on-premises assets
Why it's wrong here
Ignoring the web application and testing only on-premises assets would leave a significant attack surface untested, failing to fulfill the penetration test's objectives. This option also sidesteps the authorization problem instead of solving it—the correct response to a third-party dependency is to obtain written permission, not to avoid the asset. The web application remains in scope, and the client expects valid testing with proper legal backing.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.