Exercise 1: Why the Payment Processor Is Excluded From Scope — Possible Solution ==================================================================== WHAT THE SAMPLE RoE STATES ------------------------------ Per this chapter's own sample RoE, "payments.meridianretail.example (third-party payment processor infrastructure, NOT owned by Meridian...)" is explicitly listed under Scope — OUT. WHY THIS MATCHES PENTEST1-2'S SHARED-INFRASTRUCTURE WARNING ------------------------------ Per pentest1-2's own warn-box, "a client can genuinely, sincerely authorize testing of 'our website' without realizing that website sits on shared hosting, behind a third-party CDN, or inside a cloud environment where other systems — belonging to OTHER organizations entirely — share the same infrastructure," and testing that goes beyond what the client actually owns and controls "can mean the tester has unknowingly committed genuinely unauthorized access against a completely different organization." payments.meridianretail.example, despite using a Meridian-branded subdomain that makes it LOOK like it belongs to Meridian, is explicitly identified in the RoE as belonging to a third-party payment processor, not to Meridian itself. Meridian's own signatory has no legal authority to authorize testing of infrastructure they don't own or control — regardless of how the domain name appears, or how sincerely Meridian's own representative might believe "our payment page" is covered by "our website." THE CONCRETE RISK THIS EXCLUSION PREVENTS ------------------------------ Without this explicit exclusion, a tester who assumed "everything under the meridianretail.example domain is in scope" could end up testing the payment processor's own systems — a completely separate organization that never authorized anything at all — turning what Meridian sincerely believed was authorized testing into genuinely unauthorized access against a third party, exactly the scenario pentest1-2's warn-box described. WHY THIS WORKS AS AN ANSWER ------------------------------ It quotes the specific RoE line explaining the exclusion, and connects it directly and specifically to pentest1-2's own shared-infrastructure warning rather than treating the exclusion as an arbitrary RoE detail.