nerdexam
CompTIA

PT0-003 · Question #287

Which of the following authorizations is mandatory when a penetration tester is involved in a complex IT infrastructure?

The correct answer is A. Customer authorization. Before any penetration testing begins -- especially in a complex IT infrastructure involving multiple systems, cloud environments, and potentially shared platforms -- a formal written authorization from the customer (client organization) is mandatory. This authorization defines…

Submitted by noor.lb· Mar 6, 2026Engagement management

Question

Which of the following authorizations is mandatory when a penetration tester is involved in a complex IT infrastructure?

Options

  • ACustomer authorization
  • BPenetration tester authorization
  • CThird-party authorization
  • DInternal team authorization

How the community answered

(37 responses)
  • A
    92% (34)
  • C
    3% (1)
  • D
    5% (2)

Explanation

Before any penetration testing begins -- especially in a complex IT infrastructure involving multiple systems, cloud environments, and potentially shared platforms -- a formal written authorization from the customer (client organization) is mandatory. This authorization defines the scope, targets, timeframes, and limitations of the assessment and ensures legal protection for both the tester and the organization. Conducting testing without explicit client authorization could violate laws (e.g., Computer Fraud and Abuse Act in the U.S.) and corporate policies.

Topics

#Rules of engagement#Authorization#Ethical hacking#Legal agreements

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice