CompTIA PenTest+ (PT0-003) — All Questions
3 questions
Which document formally defines the boundaries of a penetration test, including which systems, networks, and techniques are authorized?
- a.The final vulnerability report
- b.The rules of engagement / scope agreement✓
- c.The invoice for services
- d.The tester's personal notes
The rules of engagement, together with the defined scope, formally authorize what may be tested and how, protecting both the tester and the client. Testing outside this agreement can be illegal, so scope must be established and signed before work begins.
During an engagement, a tester discovers evidence of an active, ongoing compromise by an unknown third party. According to good engagement practice, what should the tester do?
- a.Continue silently and mention it only in the final report weeks later
- b.Attempt to remove the intruder without telling anyone
- c.Ignore it because it is outside the test scope
- d.Immediately notify the client contact per the agreed communication plan✓
Discovering a live breach is a defined communication trigger, so the tester must promptly notify the designated client contact rather than delaying or acting unilaterally. The rules of engagement typically specify these escalation paths in advance for exactly this situation.
Why is written authorization from a properly empowered party essential before any testing activity begins?
- a.Without authorization, the same actions could constitute illegal unauthorized access✓
- b.It guarantees no vulnerabilities will be found
- c.It removes the need to define any scope
- d.It automatically encrypts all findings
Penetration testing techniques mirror those of real attackers, so without proper written authorization the same actions could be prosecuted as unauthorized access. Authorization from an empowered party is the legal foundation that makes an engagement legitimate.