Courseiva
Engagement Management →easyMultiple Select

PT0-002 Engagement Management Practice Question

Which THREE of the following are common components of a pre-engagement agreement between a penetration tester and a client?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rules of Engagement (RoE)

Pre-engagement typically includes SOW, RoE, NDA, permission letters, emergency contacts, and communication plans.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    List of all employee passwords

    Why it's wrong here

    Employee passwords are credentials, not legal or scoping documents. Including them in a pre-engagement agreement would be a severe security risk and violate the principle of least privilege; testers should never receive plaintext passwords as part of contract deliverables. Even in authorized password testing scenarios, credentials are obtained through legitimate testing techniques rather than being handed over in the agreement.

  • ✓

    Rules of Engagement (RoE)

    Why this is correct

    RoE is a critical pre-engagement document that defines the authorized testing boundaries, including allowed techniques, testing windows, IP ranges, emergency contacts, and prohibited actions. It establishes the legal and operational limits for the penetration test, such as whether social engineering or denial-of-service attacks are permitted. This ensures both client and tester agree on acceptable behavior, preventing scope creep and misunderstandings.

  • ✓

    Statement of Work (SOW)

    Why this is correct

    The SOW is a formal contract that specifies the objectives, deliverables, timeline, and payment terms for the penetration test. It details the exact services to be performed, such as network or web application testing, and the expected outputs like the final report and remediation recommendations. The SOW aligns expectations, ensuring both parties understand the scope, schedule, and success criteria.

  • ✓

    Non-Disclosure Agreement (NDA)

    Why this is correct

    An NDA is a legal contract that protects confidential information shared between the client and the penetration testing firm during and after the engagement. It ensures that sensitive data such as network diagrams, system vulnerabilities, and proprietary business information cannot be disclosed to unauthorized parties. This is essential for trust and compliance, as testers gain access to highly sensitive internals.

  • ✗

    Full source code of the target application

    Why it's wrong here

    Providing the full source code is not a component of the pre-engagement agreement; it is an optional input for a white-box test, not a contractual deliverable. The agreement may specify whether source code is provided, but the code itself is not part of the agreement. Black-box or gray-box testing often requires no source code, so its inclusion is a separate technical decision, not a standard contract component.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.