Courseiva
Engagement Management →mediumMultiple Choice

PT0-002 Engagement Management Practice Question

During pre-engagement, a client insists that the penetration testers sign a non-disclosure agreement (NDA). However, the client refuses to provide a 'get-out-of-jail' letter. What risk does this pose to the penetration testers?

⚠ Common exam trap

It's easy for candidates to confuse the NDA (which protects confidentiality) with the get-out-of-jail letter (which provides legal authorization), mistakenly thinking the NDA alone is sufficient to cover liability, when in fact the NDA does not grant permission to perform intrusive testing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Potential legal liability if the client or third parties perceive the testing as malicious

Without a 'get-out-of-jail' letter (also known as a authorization letter or testing waiver), the penetration testers have no documented legal authorization to perform the agreed-upon attacks. If the client or a third party (e.g., an ISP, law enforcement, or a security monitoring service) detects the test traffic and interprets it as malicious, the testers could face criminal charges or civil lawsuits for unauthorized access, even if the NDA is in place. The NDA only protects confidentiality, not the legality of the actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increased risk of data breach

    Why it's wrong here

    The authorization letter is a legal safeguard and does not alter the technical execution of the penetration test. The risk of a data breach during the test is governed by factors such as network segmentation, data handling procedures, and the tester's adherence to the rules of engagement. Signing a client letter cannot increase the inherent likelihood of a breach; it only establishes consent and defines liability.

  • ✗

    Higher likelihood of false positives

    Why it's wrong here

    False positives are artifacts of scanner configurations, signature databases, and environmental conditions, not legal authorization. The client's insistence on signing a letter does not influence how a vulnerability scanner classifies responses or how a tester manually verifies findings. Therefore, the letter has no bearing on the rate of false positives; that is a technical quality issue.

  • ✗

    Inability to use certain tools

    Why it's wrong here

    Tool usage is constrained by the agreed scope, rules of engagement, and any client-side network controls, not by the execution of an authorization letter. The letter merely grants legal permission to perform the testing; it does not enable or disable specific tools. If a tool is prohibited, that is a contractual or technical restriction, not a legal consequence of the letter's presence.

  • ✓

    Potential legal liability if the client or third parties perceive the testing as malicious

    Why this is correct

    The primary purpose of the pre-engagement authorization letter is to protect the penetration tester from allegations of unauthorized access. Without it, a client or a third party monitoring network traffic—such as an ISP or law enforcement—could reasonably perceive the scanning and exploitation activity as malicious and pursue criminal or civil charges. The letter documents informed consent, defines the exact scope, and names the responsible parties, thereby converting what might look like an attack into an authorized security assessment.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.