hardMultiple Select
PT0-002 Practice Question: During the scoping phase of a penetration test,…
During the scoping phase of a penetration test, the tester and client must define the rules of engagement (ROE). Which THREE of the following should be included in the ROE? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contact information for the client to report issues during the test.
Option A is correct because the ROE must include emergency and escalation contact information so the tester can immediately notify the client of critical findings, outages, or accidental impact during testing. Option B is correct because the ROE defines which attack types are authorized, such as phishing, social engineering, or physical intrusion, preventing the tester from exceeding the agreed scope. Option E is correct because the ROE must specify in-scope and out-of-scope boundaries, including exact IP ranges, subnets, domains, and excluded hosts, to avoid testing unauthorized systems. Option C is not included because the ROE defines authorized activities and scope, not a predetermined list of specific vulnerabilities to exploit, which is discovered during the assessment. Option D is not included because remediation steps occur after the test and belong in the final report or a separate remediation plan, not in the rules of engagement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Contact information for the client to report issues during the test.
Why this is correct
The ROE must name who the tester contacts when a critical finding or accidental outage occurs mid-test, so the client can respond quickly. Without agreed escalation contacts, the tester may continue intrusive activity while the client is unaware, breaching the engagement's communication constraint.
- ✓
Types of attacks permitted (e.g., phishing, social engineering).
Why this is correct
Specifying permitted attack types, such as phishing or social engineering, defines the authorised scope and techniques, protecting both tester and client legally. It is a core ROE element because it bounds what actions may lawfully be performed during the engagement.
- ✗
Specific vulnerabilities that will be exploited.
Why it's wrong here
The ROE defines scope, timing, targets and constraints, not which vulnerabilities will be exploited; that emerges during testing. It tempts because testers do exploit vulnerabilities, but pre-committing to specific ones would improperly restrict the assessment.
- ✗
Post-test remediation steps.
Why it's wrong here
Remediation happens after the engagement concludes, so it sits outside the rules of engagement, which govern in-scope testing conduct. It tempts because remediation guidance is a genuine deliverable, but it belongs in the final report rather than the ROE.
- ✓
Boundaries such as IP ranges and subnets to test.
Why this is correct
Defining IP ranges and subnets confines testing to authorised targets, preventing accidental impact on out-of-scope production systems. This directly satisfies the scoping requirement to establish the technical boundaries of the engagement before any exploitation begins.
Visual reference
Go deeper
Related to this question
Learn chapter
Burp Suite for Web Application Testing
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.