CompTIA PenTest+ (PT0-003)Engagement ManagementHard

During contract negotiation, a client's legal team requests a clause specifying that the client will assume responsibility for legal costs and damages if a third party sues the penetration testing firm as a direct result of testing activities that were explicitly authorized within the agreed scope. Which type of clause is being requested?

  1. AIndemnification clause
  2. BNon-disclosure clause
  3. CLimitation of liability clause
  4. DForce majeure clause
Show answer & explanation

Correct answer: A. Indemnification clause

An indemnification clause obligates one party (here, the client) to cover the other party's (the testing firm's) legal costs and damages arising from claims tied to authorized actions performed under the contract. A limitation of liability clause instead caps the testing firm's own financial exposure rather than shifting third-party claim costs to the client, an NDA governs confidentiality, and a force majeure clause addresses performance excuses due to uncontrollable events like natural disasters.

Why the other options are wrong

  • B. Protects confidential information, unrelated to legal cost responsibility for third-party suits.
  • C. Caps the testing firm's liability amount, but does not shift third-party claim costs onto the client.
  • D. Excuses contract performance due to unforeseeable events, not related to liability for lawsuits.

Indemnification Clause

A contract provision where one party agrees to compensate the other for losses, damages, or legal costs arising from claims related to actions performed under the agreement.

  • Often shields the testing firm from third-party lawsuits stemming from authorized testing
  • Differs from limitation of liability, which caps the tester's own exposure
  • Commonly paired with authorization letters and NDAs in the SOW/MSA

Memory trick: Indemnify = 'I'll shield you' from outside lawsuits

More Engagement Management questions