PT0-002 Engagement Management Practice Question
Which of the following is the primary purpose of a get-out-of-jail letter in a penetration testing engagement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To authorize the tester to perform testing activities and avoid prosecution
The get-out-of-jail letter provides legal authorization for the tester to perform activities that might otherwise be considered illegal, such as scanning or exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To protect the client from legal liability
Why it's wrong here
The authorization letter is designed to shield the tester from criminal prosecution, not to indemnify the client. A client's legal liability is typically governed by the services agreement, master service agreement, or mutual indemnification clauses, whereas the letter itself is evidence that the client consented to intrusive security testing. Thus, the purpose is to protect the tester, not the client.
- ✗
To document emergency contacts
Why it's wrong here
While the authorization letter may include contact information for the engagement, its primary purpose is not to document emergency contacts. Emergency points of contact for incidents or critical vulnerabilities are normally recorded in the Rules of Engagement or an incident response call tree. The letter's legal function is to grant permission to perform otherwise unlawful access, which is unrelated to operational emergency procedures.
- ✗
To outline the scope of the test
Why it's wrong here
The scope of a penetration test—target networks, systems, testing windows, and allowed techniques—is comprehensively defined in the Rules of Engagement or Statement of Work. Although the authorization letter may reference this scope to bound the granted permission, it is not a scoping document itself. Its core purpose is to provide legal authorization and prevent prosecution, not to outline the technical parameters of the assessment.
- ✓
To authorize the tester to perform testing activities and avoid prosecution
Why this is correct
This letter, commonly known as a 'get-out-of-jail-free' letter, explicitly authorizes the penetration tester to perform activities that would otherwise violate computer fraud and abuse laws. It provides prima facie evidence of consent from the client, protecting the tester from criminal prosecution for unauthorized access. Without this authorization, even a legitimate security test could be deemed illegal, so the letter is the primary legal safeguard for the tester.
Go deeper
Related to this question
Learn chapter
Red Team Exercises vs Penetration Tests
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.