Courseiva
hardMultiple Select

PT0-002 Practice Question: During the scoping phase of a penetration test,…

During the scoping phase of a penetration test, the tester and client must define the rules of engagement (ROE). Which THREE of the following should be included in the ROE? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Contact information for the client to report issues during the test.

Option A is correct because the ROE must include emergency and escalation contact information so the tester can immediately notify the client of critical findings, outages, or accidental impact during testing. Option B is correct because the ROE defines which attack types are authorized, such as phishing, social engineering, or physical intrusion, preventing the tester from exceeding the agreed scope. Option E is correct because the ROE must specify in-scope and out-of-scope boundaries, including exact IP ranges, subnets, domains, and excluded hosts, to avoid testing unauthorized systems. Option C is not included because the ROE defines authorized activities and scope, not a predetermined list of specific vulnerabilities to exploit, which is discovered during the assessment. Option D is not included because remediation steps occur after the test and belong in the final report or a separate remediation plan, not in the rules of engagement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Contact information for the client to report issues during the test.

    Why this is correct

    The ROE must name who the tester contacts when a critical finding or accidental outage occurs mid-test, so the client can respond quickly. Without agreed escalation contacts, the tester may continue intrusive activity while the client is unaware, breaching the engagement's communication constraint.

  • ✓

    Types of attacks permitted (e.g., phishing, social engineering).

    Why this is correct

    Specifying permitted attack types, such as phishing or social engineering, defines the authorised scope and techniques, protecting both tester and client legally. It is a core ROE element because it bounds what actions may lawfully be performed during the engagement.

  • ✗

    Specific vulnerabilities that will be exploited.

    Why it's wrong here

    The ROE defines scope, timing, targets and constraints, not which vulnerabilities will be exploited; that emerges during testing. It tempts because testers do exploit vulnerabilities, but pre-committing to specific ones would improperly restrict the assessment.

  • ✗

    Post-test remediation steps.

    Why it's wrong here

    Remediation happens after the engagement concludes, so it sits outside the rules of engagement, which govern in-scope testing conduct. It tempts because remediation guidance is a genuine deliverable, but it belongs in the final report rather than the ROE.

  • ✓

    Boundaries such as IP ranges and subnets to test.

    Why this is correct

    Defining IP ranges and subnets confines testing to authorised targets, preventing accidental impact on out-of-scope production systems. This directly satisfies the scoping requirement to establish the technical boundaries of the engagement before any exploitation begins.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.