PT0-002 Engagement Management Practice Question
During pre-engagement, a client insists that the penetration testers sign a non-disclosure agreement (NDA). However, the client refuses to provide a 'get-out-of-jail' letter. What risk does this pose to the penetration testers?
⚠ Common exam trap
It's easy for candidates to confuse the NDA (which protects confidentiality) with the get-out-of-jail letter (which provides legal authorization), mistakenly thinking the NDA alone is sufficient to cover liability, when in fact the NDA does not grant permission to perform intrusive testing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Potential legal liability if the client or third parties perceive the testing as malicious
Without a 'get-out-of-jail' letter (also known as a authorization letter or testing waiver), the penetration testers have no documented legal authorization to perform the agreed-upon attacks. If the client or a third party (e.g., an ISP, law enforcement, or a security monitoring service) detects the test traffic and interprets it as malicious, the testers could face criminal charges or civil lawsuits for unauthorized access, even if the NDA is in place. The NDA only protects confidentiality, not the legality of the actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increased risk of data breach
Why it's wrong here
The authorization letter is a legal safeguard and does not alter the technical execution of the penetration test. The risk of a data breach during the test is governed by factors such as network segmentation, data handling procedures, and the tester's adherence to the rules of engagement. Signing a client letter cannot increase the inherent likelihood of a breach; it only establishes consent and defines liability.
- ✗
Higher likelihood of false positives
Why it's wrong here
False positives are artifacts of scanner configurations, signature databases, and environmental conditions, not legal authorization. The client's insistence on signing a letter does not influence how a vulnerability scanner classifies responses or how a tester manually verifies findings. Therefore, the letter has no bearing on the rate of false positives; that is a technical quality issue.
- ✗
Inability to use certain tools
Why it's wrong here
Tool usage is constrained by the agreed scope, rules of engagement, and any client-side network controls, not by the execution of an authorization letter. The letter merely grants legal permission to perform the testing; it does not enable or disable specific tools. If a tool is prohibited, that is a contractual or technical restriction, not a legal consequence of the letter's presence.
- ✓
Potential legal liability if the client or third parties perceive the testing as malicious
Why this is correct
The primary purpose of the pre-engagement authorization letter is to protect the penetration tester from allegations of unauthorized access. Without it, a client or a third party monitoring network traffic—such as an ISP or law enforcement—could reasonably perceive the scanning and exploitation activity as malicious and pursue criminal or civil charges. The letter documents informed consent, defines the exact scope, and names the responsible parties, thereby converting what might look like an attack into an authorized security assessment.
Go deeper
Related to this question
Learn chapter
Penetration Testing Tools
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
Key term
Non-disclosure agreement
A legally binding contract that prevents one party from sharing confidential information with unauthorized individuals or entities.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.