Courseiva
Engagement Management →mediumMultiple Choice

PT0-002 Engagement Management Practice Question

During an external penetration test, the tester discovers that a critical web application is hosted on a third-party cloud provider. The SOW did not mention this provider. What should the tester do before proceeding with testing against that provider's infrastructure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Obtain written authorization from the third-party provider

Testing third-party services requires explicit permission from the provider to avoid legal and contractual issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Obtain written authorization from the third-party provider

    Why this is correct

    Obtaining written authorization from the third-party provider is mandatory because the provider owns or controls the asset; without their explicit consent, testing constitutes unauthorized access, potentially violating computer fraud laws and civil agreements. This authorization must be documented in the rules of engagement and ideally obtained before any testing begins, as the client's scope alone cannot transfer ownership rights.

  • ✗

    Scan only the IP addresses that resolve to the client's domain

    Why it's wrong here

    Scanning only IP addresses that resolve to the client's domain is insufficient because the web application may be hosted on shared infrastructure, a CDN, or a cloud provider where the underlying servers are not owned by the client. Even if the DNS record points to the client's subdomain, the provider retains administrative control, and scanning those IPs without their permission is still unauthorized and may be illegal.

  • ✗

    Continue testing as long as the target is in scope

    Why it's wrong here

    Continuing testing solely because the target is in scope is dangerous because scope is defined by the client, but the client cannot grant permission for assets they do not own. Penetration testers must verify that every in-scope asset is either owned by the client or covered by explicit third-party authorization; otherwise, they risk violating the Computer Fraud and Abuse Act or the provider's terms of service, which can lead to legal action and loss of credentials.

  • ✗

    Ignore the web application and test only on-premises assets

    Why it's wrong here

    Ignoring the web application and testing only on-premises assets would leave a significant attack surface untested, failing to fulfill the penetration test's objectives. This option also sidesteps the authorization problem instead of solving it—the correct response to a third-party dependency is to obtain written permission, not to avoid the asset. The web application remains in scope, and the client expects valid testing with proper legal backing.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.