mediumMultiple Choice
PT0-002 Practice Question: A penetration testing firm is hired to perform a…
A penetration testing firm is hired to perform a test on a multinational company that has offices in Europe and North America. The client wants to test all systems including those in the European office, which is subject to GDPR. Which of the following is the MOST important legal consideration to include in the rules of engagement?
⚠ Common exam trap
A common mix-up: candidates choose a non-disclosure agreement (NDA) as the most important legal consideration, confusing general confidentiality with the specific data protection obligations required by GDPR, which are distinct and more prescriptive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data protection and privacy clauses addressing handling of personal data
The engagement involves testing systems in a European office subject to GDPR, which imposes strict requirements on the processing and protection of personal data. The rules of engagement must include data protection and privacy clauses to define how the penetration tester will handle any personal data encountered during the test, ensuring compliance with GDPR Article 5 (lawfulness, fairness, transparency) and Article 32 (security of processing). Without these clauses, the tester could inadvertently violate GDPR by collecting or storing personal data without a lawful basis, exposing both the client and the testing firm to significant fines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A limitation of liability clause
Why it's wrong here
Limitation of liability allocates financial risk between tester and client; it does not address the lawful basis for processing EU personal data under GDPR. It is tempting because liability clauses appear in every contract, and would be correct where the client's priority is capping damages rather than meeting data-protection obligations.
- ✓
Data protection and privacy clauses addressing handling of personal data
Why this is correct
GDPR governs processing of EU residents' personal data, so the rules of engagement must include data protection and privacy clauses specifying lawful handling, storage, and disposal of any personal data encountered during testing across European systems.
- ✗
A non-disclosure agreement
Why it's wrong here
NDA is important for confidentiality but does not specifically address data protection requirements under GDPR.
- ✗
A schedule of testing hours
Why it's wrong here
Testing hours manage operational disruption and availability, not the lawful processing of EU personal data that GDPR governs. Scheduling windows are the correct rules-of-engagement element when the client's concern is avoiding peak-hour outages, making this plausible but unrelated to the cross-border data-protection requirement in the stem.
Go deeper
Related to this question
Learn chapter
CVSS Scoring in Penetration Test Reports
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on PT0-003
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A penetration tester is scoping a test for a multinational company that must comply with GDPR. The tester wants to ensure that any personal data captured during the test is handled appropriately. Which document should be reviewed?
medium- A.Test plan
- B.Authorization letter
- ✓ C.Data processing agreement
- D.Non-disclosure agreement
Why C: A data processing agreement (DPA) outlines how personal data is processed and protected, which is essential for GDPR compliance. An NDA covers confidentiality but not data processing specifics. An authorization letter grants permission, and a test plan is technical.
Variation 2. A penetration tester is scoping a test for a multinational corporation that has offices in the United States and the European Union. The client wants to test the entire environment. Which of the following is the MOST important legal consideration for the tester to include in the rules of engagement?
medium- A.Ensuring all testing is performed from a single external IP address
- B.Obtaining explicit written authorization from each country's legal department
- ✓ C.Ensuring compliance with GDPR and data protection laws
- D.Restricting testing to non-business hours to minimize impact
Why C: The multinational corporation operates in the European Union, where the General Data Protection Regulation (GDPR) imposes strict requirements on the processing and transfer of personal data. A penetration test that accesses or stores EU residents' personal data must comply with GDPR, including data minimization, lawful processing, and breach notification obligations. Failure to include GDPR compliance in the rules of engagement could result in severe fines (up to 4% of annual global turnover) and legal liability for the tester and client.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.