CompTIA PenTest+ (PT0-003)Engagement ManagementHard

While running an authorized nmap scan against a client's approved /24 subnet, a tester discovers a live host with an IP address that falls just outside the documented scope but appears to be owned by the same client. What is the correct next step before scanning or exploiting that host?

  1. AUse Metasploit to exploit the host and disclose it later in the report
  2. BScan the host immediately since it clearly belongs to the client
  3. CIgnore the host entirely and omit it from the report
  4. DHalt testing of that host and obtain written client approval via a scope addendum
Show answer & explanation

Correct answer: D. Halt testing of that host and obtain written client approval via a scope addendum

Testing an asset outside the documented scope, even if it appears related, requires the tester to pause and obtain explicit written authorization, typically through a signed scope change/addendum, before any scanning or exploitation occurs. This protects both the tester and client legally and ensures activity stays authorized.

Why the other options are wrong

  • A. Exploiting first and disclosing later is both unethical and potentially illegal without prior authorization.
  • B. Scanning without written approval could constitute unauthorized access, regardless of apparent ownership.
  • C. Ignoring a potentially significant discovery fails the client and does not follow proper scope change procedures.

Scope Change Management

The formal process of pausing testing on newly discovered out-of-scope assets and obtaining written client approval before proceeding.

  • Even 'obviously related' assets require explicit written authorization
  • Typically documented via a signed scope addendum to the SOW
  • Protects both tester and client from legal exposure

Memory trick: See it, Stop it, Send it (to client), Sign it, Scan it — five steps for out-of-scope finds.

More Engagement Management questions