nerdexam
CompTIA

PT0-003 · Question #42

During a web application assessment, a penetration tester identifies an administrative tool that would allow for the production database to be deleted without authorization. Which of the following…

The correct answer is A. Rules of engagement. The rules of engagement (ROE) define what is allowed or restricted during the penetration test, including whether potentially destructive actions (like deleting a production database) are permitted. Before proceeding with such a high-risk activity, the tester must refer to the…

Submitted by hans_de· Mar 6, 2026Engagement Management

Question

During a web application assessment, a penetration tester identifies an administrative tool that would allow for the production database to be deleted without authorization. Which of the following is most important for the penetration tester to consider before proceeding with testing?

Options

  • ARules of engagement
  • BBusiness continuity planning
  • CAgreed-upon testing hours
  • DApplication terms of use

How the community answered

(35 responses)
  • A
    83% (29)
  • B
    6% (2)
  • C
    9% (3)
  • D
    3% (1)

Explanation

The rules of engagement (ROE) define what is allowed or restricted during the penetration test, including whether potentially destructive actions (like deleting a production database) are permitted. Before proceeding with such a high-risk activity, the tester must refer to the ROE to avoid unauthorized or damaging actions.

Topics

#rules of engagement#scope management#destructive testing

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice