PT0-002 Engagement Management Practice Question
Which THREE of the following are common components of a pre-engagement agreement between a penetration tester and a client?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rules of Engagement (RoE)
Pre-engagement typically includes SOW, RoE, NDA, permission letters, emergency contacts, and communication plans.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
List of all employee passwords
Why it's wrong here
Employee passwords are credentials, not legal or scoping documents. Including them in a pre-engagement agreement would be a severe security risk and violate the principle of least privilege; testers should never receive plaintext passwords as part of contract deliverables. Even in authorized password testing scenarios, credentials are obtained through legitimate testing techniques rather than being handed over in the agreement.
- ✓
Rules of Engagement (RoE)
Why this is correct
RoE is a critical pre-engagement document that defines the authorized testing boundaries, including allowed techniques, testing windows, IP ranges, emergency contacts, and prohibited actions. It establishes the legal and operational limits for the penetration test, such as whether social engineering or denial-of-service attacks are permitted. This ensures both client and tester agree on acceptable behavior, preventing scope creep and misunderstandings.
- ✓
Statement of Work (SOW)
Why this is correct
The SOW is a formal contract that specifies the objectives, deliverables, timeline, and payment terms for the penetration test. It details the exact services to be performed, such as network or web application testing, and the expected outputs like the final report and remediation recommendations. The SOW aligns expectations, ensuring both parties understand the scope, schedule, and success criteria.
- ✓
Non-Disclosure Agreement (NDA)
Why this is correct
An NDA is a legal contract that protects confidential information shared between the client and the penetration testing firm during and after the engagement. It ensures that sensitive data such as network diagrams, system vulnerabilities, and proprietary business information cannot be disclosed to unauthorized parties. This is essential for trust and compliance, as testers gain access to highly sensitive internals.
- ✗
Full source code of the target application
Why it's wrong here
Providing the full source code is not a component of the pre-engagement agreement; it is an optional input for a white-box test, not a contractual deliverable. The agreement may specify whether source code is provided, but the code itself is not part of the agreement. Black-box or gray-box testing often requires no source code, so its inclusion is a separate technical decision, not a standard contract component.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.