easyMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A client is planning a penetration test of their…
A client is planning a penetration test of their AWS cloud environment. They will provide the tester with an IAM user account with limited permissions. Which of the following scoping restrictions is most important to include in the rules of engagement to avoid unexpected costs?
⚠ Common exam trap
The trap here is that candidates may focus on technical restrictions like service tiers or support permissions, overlooking the direct financial risk of resource creation, which is the most critical scoping concern in cloud penetration testing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The tester must not create any new AWS resources that incur costs.
Creating new AWS resources (e.g., EC2 instances, RDS databases, Lambda functions) can incur direct costs under the tester's IAM user account, even with limited permissions. The rules of engagement must explicitly prohibit resource creation to prevent unexpected billing, as AWS charges for resources provisioned regardless of the test's purpose. This scoping restriction aligns with the principle of cost containment in penetration testing engagements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The tester must not create any new AWS resources that incur costs.
Why this is correct
The restriction that the tester must not create any new AWS resources that incur costs is a core cost-control measure in cloud penetration testing. Launching EC2 instances, RDS databases, or even ephemeral resources for vulnerability scanning can rack up charges rapidly, especially if left running. This constraint forces the tester to work within the client's existing environment, using serverless functions or pre-provisioned test instances, and to rely on AWS budget alerts and billing monitoring to avoid financial surprise.
- ✗
The tester must use only premium AWS services for testing.
Why it's wrong here
Requiring 'premium' AWS services for testing is nonsensical because standard services like EC2, S3, IAM, and CloudTrail are the very ones the client likely uses and need tested. Premium support tiers or enterprise-grade services do not inherently improve test efficacy; they only add unnecessary cost and operational overhead. The tester should select services based on the scope and reproduction of the client's actual architecture, not on a premium designation.
- ✗
The tester must request permission from AWS Support before each test.
Why it's wrong here
Seeking permission from AWS Support before each test is both impractical and semantically wrong; AWS Support is not the authorization owner for a customer's account. The client, as the account owner, grants explicit authorization for penetration testing, and AWS's Customer Agreement already permits such testing within the customer's own environment, provided the tester adheres to AWS's authorized testing guidelines. What the tester should do instead is confirm scope and authorization with the client and ensure they avoid prohibited activities like DDoS or attacks that could impact other AWS customers.
- ✗
The tester must avoid testing in the us-east-1 region due to higher costs.
Why it's wrong here
The claim that us-east-1 is 'higher cost' is false; in fact, us-east-1 historically has the most competitive pricing among AWS regions and serves as the baseline for price comparisons. Regional price variance is minimal (often fractions of a cent per compute-hour), so avoiding a region on cost grounds misses the real risk: resource creation. The correct approach is to ensure any resources created are immediately cleaned up or protected by budget limits, regardless of which region the engagement targets.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Rules of engagement
Rules of engagement are the documented guidelines that define the scope, boundaries, and authorized actions a security tester may take during a penetration test or security assessment.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 185 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.