PT0-002 Engagement Management Practice Question
Which legal framework in the United States prohibits unauthorized access to computer systems and is commonly referenced in penetration testing authorization documents?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CFAA
The Computer Fraud and Abuse Act (CFAA) is the primary U.S. law against unauthorized computer access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HIPAA
Why it's wrong here
HIPAA, the Health Insurance Portability and Accountability Act, governs the privacy and security of protected health information by covered entities and their business associates. Its rules mandate administrative, physical, and technical safeguards for medical records, but they do not establish a general prohibition on unauthorized computer access. While a violation involving unlawful access to health data could trigger HIPAA penalties, the statute is not the federal framework designed to address hacking or unauthorized system access broadly.
- ✗
GLBA
Why it's wrong here
The Gramm-Leach-Bliley Act (GLBA) imposes data privacy and security obligations specifically on financial institutions, including the Safeguards Rule that requires a written information security program. GLBA also prohibits 'pretexting,' a form of social engineering used to obtain customer financial information. However, GLBA is not an anti-hacking statute; it focuses on regulating the collection, sharing, and protection of consumer financial data rather than providing a broad prohibition against unauthorized computer access.
- ✓
CFAA
Why this is correct
The Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. §1030, is the primary U.S. federal statute prohibiting unauthorized access to computers and protected systems. It criminalizes intentionally accessing a computer without authorization, or exceeding authorized access, to obtain information, cause damage, or commit fraud. This makes CFAA the legal framework that directly targets unauthorized computer access, which is why it is the correct answer.
- ✗
SOX
Why it's wrong here
The Sarbanes-Oxley Act (SOX) was enacted to restore investor confidence after corporate accounting scandals by tightening corporate governance, audit independence, and financial disclosure requirements for public companies. It establishes penalties for financial fraud and requires management to assess internal controls, but it has no provisions addressing unauthorized computer access or network intrusion. SOX is irrelevant here because it deals with financial reporting integrity, not cybercrime.
Go deeper
Related to this question
Learn chapter
Re-Testing and Validation Testing
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.