hardMultiple Choice
PT0-002 Practice Question: During scoping, a tester learns that the client's…
During scoping, a tester learns that the client's network has multiple subsidiaries with different IP ranges. The client wants a test that covers all subsidiaries but with a limited number of target IPs. How should the tester proceed?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Select a representative sample of IPs from each subsidiary
Selecting a representative sample of IPs from each subsidiary allows coverage across all subsidiaries while respecting the target limit. Testing only headquarters ignores subsidiaries, and combining ranges may produce too many targets. Asking for a larger budget may not be an option.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ask for a larger budget
Why it's wrong here
Requesting a larger budget does not resolve the actual scoping constraint, which is the maximum number of IP addresses or hosts that can be tested within the engagement's time and resource limits. A bigger budget might expand the total scope, but it does not address the immediate need to prioritize coverage across multiple subsidiaries when the client's network exceeds the agreed-upon test boundary. Scoping decisions are driven by risk assessment and technical feasibility, not solely by financial resources, and the tester must work within the defined parameters to select an appropriate subset of targets.
- ✓
Select a representative sample of IPs from each subsidiary
Why this is correct
Selecting a representative sample of IP addresses from each subsidiary ensures that every business unit receives some level of security coverage while adhering to the maximum host limit. This stratified sampling approach reduces the risk of missing critical vulnerabilities in any one subsidiary, as each location's unique network segment and potential weaknesses are at least partially examined. The sample should be chosen based on risk factors such as asset criticality, exposure to the internet, and historical incident data, making the test results more statistically valid and aligned with the client's goal of covering all subsidiaries.
- ✗
Test only the corporate headquarters and ignore subsidiaries
Why it's wrong here
Testing only the corporate headquarters and ignoring subsidiaries fails to meet the client's explicit requirement to cover all subsidiaries, leaving significant portions of the attack surface unassessed. Subsidiaries often have their own network infrastructure, security controls, and local threat exposure, so a headquarters-only test would produce a false sense of security for the entire organization. This approach also violates the principle of comprehensive scoping, as the engagement's objectives and legal boundaries typically require explicit coverage of all in-scope entities to avoid overlooking high-risk assets.
- ✗
Use a subnet calculator to combine all ranges
Why it's wrong here
Using a subnet calculator to combine all IP ranges might create a single supernet that exceeds the maximum number of testable hosts, and it could also merge subnets that belong to different subsidiaries with distinct security contexts. Even if the combined range fits within the limit, it does not guarantee proportional representation of each subsidiary; for example, a large subsidiary's range would dominate, while smaller ones might be underrepresented or completely excluded. The tester must instead manually curate a representative set of IPs from each subsidiary to satisfy the client's coverage requirement while respecting the scoping cap.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.