nerdexam
CompTIA

PT0-003 · Question #290

A penetration testing company is defining the rules of engagement with a client. Which of the following should the company include?

The correct answer is D. Authorization letter. While several items listed are important parts of an overall engagement package, the authorization letter (often called written authorization, engagement letter, or authorization to test) is mandatory before testing begins -- it explicitly grants permission to test specified…

Submitted by marco_it· Mar 6, 2026Engagement management

Question

A penetration testing company is defining the rules of engagement with a client. Which of the following should the company include?

Options

  • ANon-disclosure agreement
  • BEscalation process
  • CURL list
  • DAuthorization letter

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    3% (1)
  • D
    91% (32)

Explanation

While several items listed are important parts of an overall engagement package, the authorization letter (often called written authorization, engagement letter, or authorization to test) is mandatory before testing begins -- it explicitly grants permission to test specified systems under defined scope and constraints and provides legal protection for both parties. An RoE typically references or attaches the NDA (A), includes escalation/contact processes (B), and provides target lists (C), but without the formal authorization letter the engagement should not

Topics

#Rules of engagement#Authorization letter#Legal agreements#Engagement planning

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice