CREST CREST Legal, Compliance & Professional Standards 2 — Questions and Answers
Question 1: What should a CREST tester do immediately upon discovering evidence of an active criminal intrusion during an authorized engagement?
- Continue testing and document findings in the final report
- Stop testing and escalate to the client's incident response contact immediately (Correct answer)
- Attempt to remove the attacker from the system
- Post findings to a public disclosure platform
Correct answer: Stop testing and escalate to the client's incident response contact immediately
Discovering an active third-party intrusion requires immediate escalation to the client's designated emergency contact to initiate incident response without destroying evidence.
Question 2: Under PCI DSS, how often must external penetration testing be performed on cardholder data environments?
- Monthly
- Quarterly
- At least annually and after significant infrastructure changes (Correct answer)
- Every two years
Correct answer: At least annually and after significant infrastructure changes
PCI DSS Requirement 11.4 mandates external and internal penetration testing at least once per year and after any significant infrastructure or application upgrade.
Question 3: Which principle of professional ethics requires a CREST assessor to disclose any conflicts of interest before accepting an engagement?
- Competence
- Objectivity and independence (Correct answer)
- Confidentiality
- Due diligence
Correct answer: Objectivity and independence
Objectivity and independence requires testers to disclose relationships or interests that could impair their impartial judgment before undertaking an assessment.
Question 4: What does the concept of 'scope creep' mean in a penetration testing engagement, and why is it legally significant?
- Adding more testers than planned
- Testing systems beyond the authorized scope, which may violate the CFAA (Correct answer)
- Exceeding the agreed budget
- Using more aggressive tools than planned
Correct answer: Testing systems beyond the authorized scope, which may violate the CFAA
Scope creep involves accessing or testing systems not explicitly authorized, potentially constituting unauthorized access under the CFAA regardless of intent.
Question 5: Which framework provides a structured approach for responsible vulnerability disclosure that balances public safety with vendor response time?
- OWASP Top 10
- Coordinated Vulnerability Disclosure (CVD) (Correct answer)
- NIST RMF
- ISO 27005
Correct answer: Coordinated Vulnerability Disclosure (CVD)
Coordinated Vulnerability Disclosure (CVD) defines a process where researchers notify vendors privately, allowing time to patch before public disclosure.
Question 6: What is the primary purpose of maintaining detailed testing logs during a CREST penetration test?
- To bill clients accurately for time spent
- To provide evidence of authorized activities and support client remediation (Correct answer)
- To satisfy CREST membership renewal requirements
- To create training material for junior testers
Correct answer: To provide evidence of authorized activities and support client remediation
Detailed logs document authorized activities, timestamps, and findings, providing evidence of scope compliance and supporting the client's remediation efforts.
What should a CREST tester do immediately upon discovering evidence of an active criminal intrusion during an authorized engagement?