Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIAPenTest+

Domain 1Objective 2

Legal and Ethical Compliance PT0-003 Practice Questions (Page 3)

Part of the Engagement management domain, which accounts for 13% of the PT0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
3concepts
13%of the exam

Questions 11–15

  1. 11expert · hard

    A penetration tester is hired by a company to test its network. The company has a strict policy that all testing must be performed from a specific IP address. The authorization letter includes this IP address. However, during the test, the tester's VPN connection drops, and the tester reconnects using a different IP address. What should the tester do?

    Select an answer first
  2. 12application · medium

    A penetration tester is hired to assess a healthcare organization's patient portal. The organization is subject to HIPAA. The tester has a signed authorization letter but the letter does not mention HIPAA compliance. What should the tester do to ensure regulatory adherence?

    Select an answer first
  3. 13application · medium

    A penetration tester is hired to test a company's cloud infrastructure. The company uses a cloud provider that has specific terms of service regarding penetration testing. What should the tester do?

    Select an answer first
  4. 14application · medium

    A penetration tester is about to start an engagement with a new client. The client has provided a signed authorization letter, but the tester notices that the letter does not include the names of the testers who will be performing the work. What should the tester do?

    Select an answer first
  5. 15application · medium

    A penetration tester is conducting an assessment for a financial institution. During the test, the tester discovers evidence of an ongoing data breach that involves customer financial records. The authorization letter does not mention any specific reporting requirements for such discoveries. What should the tester do first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “PT0-003” is a trademark of its owner, used for identification only.