Home > Glossary > CompTIA PenTest+ > Scope Creep

📖 What is Scope Creep?

Scope Creep refers to the uncontrolled expansion of a project's goals or requirements without corresponding adjustments to time, budget, or resources. In penetration testing, this often occurs when a client requests additional systems or networks be tested mid-engagement without a formal contract amendment.

🥋 Sensei Says:

"Always document scope changes in writing. If you test a system not explicitly listed in the SOW, you are technically performing an unauthorized intrusion."

📚 Certification: CompTIA PenTest+ (PT0-002)

🔑 What are the Key Concepts of Scope Creep?

  • The Statement of Work (SOW) serves as the legal baseline; any deviation from this document without a formal amendment constitutes scope creep.
  • Testing assets outside the defined scope can lead to severe legal consequences, as it may be viewed as an unauthorized intrusion.
  • Scope creep often leads to resource exhaustion, where the tester spends time on unplanned tasks, risking the quality and deadline of the report.
  • A formal change control process is essential for managing scope changes, ensuring that budget, time, and resources are adjusted to match new requirements.

🎯 How does Scope Creep appear on the PT0-002 Exam?

A scenario might describe a client asking you to 'quickly check' one additional server during an engagement. You must identify this as scope creep and select the option to request a formal SOW amendment.

You may be asked how to respond when discovering a critical vulnerability on a system that was not explicitly listed in the original scope of work, focusing on communication and documentation.

❓ Frequently Asked Questions

What is the difference between scope creep and a 'pivot' during an engagement?

Pivoting is a technical maneuver where a tester moves from one compromised system to another within the agreed boundaries. Scope creep is a project management failure where the project's goals or assets expand without formal approval.


How should a penetration tester handle a client's urgent request to add a system mid-test?

The tester should inform the client that the request falls outside the current SOW. They must then initiate the formal change control process to document the addition and adjust the timeline and budget.

Related Terms from CompTIA PenTest+

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Scope Creep? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium