easyMultiple ChoiceObjective-mapped
Third-Party API Testing — Obtaining Written Authorization
A penetration testing firm is hired to assess a client's web application that integrates with a third-party payment processor's API. The client wants to include the payment processor's API in the test scope. Which action should the tester take FIRST?
Quick Answer
The correct first action is to request written permission from the payment processor, because the API is owned and operated by a third party, not the client. Testing a third-party API without explicit authorization could violate the Computer Fraud and Abuse Act (CFAA) and the payment processor’s terms of service, exposing both the tester and the client to legal liability. On the CompTIA PenTest+ PT0-002 exam, this scenario tests your understanding of scope and legal boundaries—specifically that obtaining permission to test third-party API endpoints must come from the API owner, not just the client. A common trap is assuming the client’s authorization covers all integrated services, but the key distinction is system ownership. Remember the mnemonic “Third-party, third-party permission”—if the system belongs to someone else, you need their written go-ahead before touching it.
⚠ Common exam trap
A common mix-up: candidates assume the client's request automatically grants legal authority to test any integrated system, overlooking the critical distinction between ownership and integration in scoping agreements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request written permission from the payment processor
The correct first action is to request written permission from the payment processor because the API is owned and operated by a third party, not the client. Testing a third-party API without explicit authorization could violate the Computer Fraud and Abuse Act (CFAA) and the payment processor's terms of service, potentially leading to legal liability for both the tester and the client. The scope of a penetration test must be legally defined and agreed upon by all parties whose systems are being tested.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Begin testing the API because it is part of the client's environment
Why it's wrong here
This is incorrect because testing a third-party service without authorization is illegal and could breach contracts.
- ✓
Request written permission from the payment processor
Why this is correct
This is the correct first step. The tester must obtain explicit permission from the third party to ensure legal and ethical testing.
- ✗
Only test the client's internal systems, excluding the API
Why it's wrong here
This ignores the client's requirement to test the API; if permission can be obtained, it should be included.
- ✗
Use the payment processor's sandbox environment without notifying them
Why it's wrong here
Even sandbox environments are subject to terms of use; unauthorized testing is still not allowed.
Go deeper
Related to this question
Learn chapter
Penetration Testing Methodology
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on PT0-003
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A client hires a penetration testing firm to assess a web application that integrates with a third-party API for payment processing. The client wants to include the API endpoint in the test scope. What should the penetration tester do FIRST to ensure the test is conducted ethically and legally?
medium- A.Assume the client has already obtained permission from the API provider
- ✓ B.Obtain written authorization from the third-party API provider
- C.Rely on the client's statement that the API is within scope
- D.Test only the client's application code and ignore the API
Why B: The penetration tester must obtain explicit written authorization from the third-party API provider before testing. Without this, testing the API endpoint could violate the Computer Fraud and Abuse Act (CFAA) or similar laws, as the tester would be accessing a system they do not own or have contractual permission to test. The client's scope inclusion does not grant legal access to the third-party's infrastructure.
Variation 2. A penetration tester is hired to assess a web application that integrates with a third-party payment API. The client wants the API included in the test but does not have a signed agreement with the vendor. What is the most appropriate action for the tester?
medium- ✓ A.Ask the client to obtain a written authorization from the third-party vendor before testing the API.
- B.Proceed with testing the API using anonymous techniques to avoid detection.
- C.Test only the client's application logic but not the actual API endpoint.
- D.Include the API in the test because the client owns the integration.
Why A: Testing a third-party API without explicit written authorization from the vendor violates legal and contractual boundaries, potentially constituting unauthorized access under laws like the Computer Fraud and Abuse Act (CFAA). The penetration tester must obtain signed authorization to ensure the test is legally defensible and within scope, as the client cannot grant permission for assets they do not own.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.