2.1 Scope, Rules of Engagement, and Agreements

Key Takeaways

  • PT0-003 Domain 1 (Engagement Management) is 13% of the exam; a scan against the wrong CIDR, outside the testing window, or without written permission is unauthorized access, not a finding.
  • Scope is limited by privacy and security regulations, frameworks, and standards (for example HIPAA, GDPR, PCI DSS, ISO 27001, NIST) even when a client wants everything tested.
  • Rules of engagement must document exclusions, the escalation process (including an emergency stop), and the testing window before any scan or exploit starts.
  • An MSA (master agreement) sets the ongoing commercial relationship; a statement of work defines this engagement's targets, deliverables, and timeline.
  • An NDA protects confidential data learned during the test but does not authorize attacking systems; provider terms of service can still forbid a test the customer signed.
Last updated: August 2026

Pre-engagement work is the unglamorous part of CompTIA PenTest+ Domain 1, and it is also where engagements and careers die. Engagement Management is 13 percent of PT0-003. Objective 1.1 asks you to summarize pre-engagement activities because a technically perfect exploit against the wrong network, at the wrong hour, or without written permission is not a finding — it is unauthorized access. Treat scope, rules of engagement (RoE), and agreements as the control plane of the test. They decide what is legal before any scanner process starts.

Scope definition: privacy and security constraints

Scope answers two questions: what may we touch, and under which constraints? PT0-003 groups the first inputs as regulations, frameworks, and standards covering privacy and security. Those clauses are not decoration in a SoW appendix. They can forbid techniques, forbid data retention, require extra approvals, or force synthetic test accounts instead of production identities.

Privacy constraints govern personal data: names, email addresses, government IDs, account numbers, health records, precise location, and cardholder data. A hospital that wants its patient portal tested is still bounded by HIPAA: minimum-necessary access, a business associate agreement if testers will see electronic protected health information (ePHI), and a hard answer to whether production records may be copied into a laptop notes folder. A European SaaS tenant may be subject to GDPR, under which a screenshot of a users table is personal-data processing, not just a pretty evidence file. Consumer brands may sit under CCPA/CPRA-style rules that limit how long you keep resident data. Payment environments pull in PCI DSS duties to protect account data while still showing that the cardholder data environment was tested.

Security constraints govern how systems must be protected and how testing itself is controlled. ISO/IEC 27001 and SOC 2 Type II programs often require independent testing of named controls and a paper trail of authorization. The NIST Cybersecurity Framework and CIS Controls give the client a language to map findings. NIST SP 800-115 describes technical testing techniques and is the sort of how-we-test standard a mature RoE will cite. PCI DSS, FedRAMP, and similar programs can prohibit denial-of-service, require notice to a cloud provider, or restrict tests that could affect other tenants.

Exam trap: a vice president cannot waive a statute. If the client says to ignore GDPR because this is only a lab, you document the legal constraint, reduce collection, anonymize, or decline. Scope is the intersection of what the client wants and what the law and third-party contracts allow.

Rules of engagement: exclusions, escalation, and testing window

CompTIA's PT0-003 RoE bullets are exclusions, escalation process, and testing window. Inclusions still must be written — never infer them from a marketing site — but exam items and incident reports hammer those three named controls.

Exclusions are assets, people, or techniques you must not touch. Common exclusions include a third-party payment processor, a production database cluster, industrial control or medical devices, ISP-managed routers, a partner VPN, executive laptops, and a ban on phishing customers or partner help desks. Exclusions exist because someone else owns the system, because availability is too fragile, or because a regulator forbids the method. If the SoW authorizes 10.4.0.0/16 and excludes the payment processor, a processor interface that happens to live inside that CIDR is still out of scope. The prefix is a candidate set; the exclusion list is a veto.

Escalation process is who you call, on what channel, and what you stop doing when the test collides with reality. Triggers include a crashed host, a suspected ransomware foothold already in production, possible illegal content, a defender launching incident response against you, or a third party opening an abuse ticket. RoE should name a 24/7 client owner, a tester emergency contact, an out-of-band path that does not depend on the network you might have just broken, and an emergency stop that pauses all scanning and exploitation. Live-fire escalation is not the same as the later written report workflow; this is the brake during the window.

Testing window is the approved clock, including timezone. A realistic contract is Saturday 01:00–05:00 local time so batch jobs, backups, and on-call staff are predictable. A Nessus job still sending probes at 05:30 is out of scope in time even when every IP is in scope in space. If the work must overrun, you stop, escalate, and obtain a written window extension. A sleepy sysadmin typing sure in chat is not an amendment.

RoE should also state data handling (encrypted evidence stores, screenshot redaction, retention and purge dates), whether the test is overt or covert, scan-intensity limits, and whether production credentials may be used. Those clauses support the three official bullets; they do not replace them.

Agreement types: NDA, MSA, SoW, and ToS

PT0-003 lists four agreement types. Memorize what each one does and, just as often, what it does not do. CompTIA's objectives PDF labels the commercial umbrella a master agreement (MSA); industry language usually says master service agreement.

AgreementWhat it typically governsWhat it does not do
Non-disclosure agreement (NDA)Confidentiality of architecture, credentials, findings, and customer data learned during the workAuthorize scanning or exploitation; list CIDR ranges; replace RoE
Master service agreement / master agreement (MSA)Ongoing commercial relationship: rates, invoicing, insurance, limitation of liability, intellectual property, dispute venueDefine this week's targets, exclusions, or testing window
Statement of work (SoW)This engagement: objectives, in-scope assets, exclusions, deliverables, timeline, staffing, and usually a pointer to RoEOverride a cloud provider's terms of service or a missing authorization letter
Terms of service (ToS)A platform, cloud, or SaaS provider's posted rules for how its service may be used and testedA customer's signature on a SoW cannot legalize a test the provider forbids

Practical order: NDA so you can talk, MSA so you are a vendor, SoW so this test has a scope, RoE so operators have rules, provider ToS checks for every cloud or SaaS target, and a written authorization letter so defenders and law enforcement can see permission. If the SoW and a hallway request conflict, the written SoW wins until it is amended in writing.

Worked scenario: Saturday SaaS window

A SaaS client's SoW lists 10.4.0.0/16 plus app.example.com, excludes the payment processor and the production database cluster, and sets testing to 01:00–05:00 local Saturday.

At 02:10 Nessus, pointed at 10.4.0.0/16, starts hitting an IP that the asset inventory and reverse DNS identify as the payment processor. Stop. CIDR membership does not cancel an exclusion. Scanning a processor can disrupt cardholder systems owned by a company that never signed your SoW, and it can become an unauthorized-access event against that third party.

At 05:30 a tester is still working app.example.com because a session is almost a shell. Stop. The window closed. Continuing is out-of-scope testing even against an in-scope URL. Escalate, record the stop time, and request a written extension if the client still wants the chain completed.

Wrong target and wrong time are the two highest-frequency pre-engagement failures on the exam and in after-action reports. Documents first; packets second.

Loading diagram...
Pre-engagement documents before testing starts
Test Your Knowledge

A consulting firm already has a master service agreement with a bank covering rates, insurance, and limitation of liability. This week's penetration test still needs named targets, exclusions, deliverables, and a Saturday testing window. Which document should define those engagement-specific details?

A
B
C
D
Test Your Knowledge

A SaaS SoW authorizes 10.4.0.0/16 plus app.example.com, excludes the payment processor and production database cluster, and sets the testing window to 01:00–05:00 local Saturday. Nessus is still scanning at 05:30, and one live host in the CIDR is the payment processor. What should the tester do?

A
B
C
D
Test Your Knowledge

Which statement correctly describes a non-disclosure agreement in a penetration-test engagement?

A
B
C
D