CREST CREST Legal, Compliance & Professional Standards 1 — Questions and Answers
Question 1: Under the US Computer Fraud and Abuse Act (CFAA), what is the primary legal requirement before conducting a penetration test?
- Filing a report with the FBI
- Obtaining written authorization from the system owner (Correct answer)
- Registering with a government agency
- Completing a CREST certification
Correct answer: Obtaining written authorization from the system owner
The CFAA prohibits unauthorized access to computer systems, so written authorization from the system owner is legally required before any penetration testing.
Question 2: What document formally defines the scope, objectives, timeline, and legal permissions for a penetration test engagement?
- NDA
- Statement of Work (SoW) / Rules of Engagement (Correct answer)
- Vulnerability disclosure policy
- Security audit report
Correct answer: Statement of Work (SoW) / Rules of Engagement
The Statement of Work and Rules of Engagement document outlines all authorized activities, IP ranges, test windows, and escalation contacts for a penetration test.
Question 3: Which CREST code of conduct principle requires members to report discovered vulnerabilities responsibly and not exploit them beyond what is authorized?
- Commercial competence
- Ethical behavior and integrity (Correct answer)
- Technical knowledge
- Financial accountability
Correct answer: Ethical behavior and integrity
CREST's ethical behavior and integrity principle prohibits members from exploiting vulnerabilities beyond authorized scope or for personal gain.
Question 4: In the US, which regulation specifically governs the privacy and security of protected health information (PHI) in electronic form?
- SOX
- GLBA
- HIPAA/HITECH (Correct answer)
- FERPA
Correct answer: HIPAA/HITECH
HIPAA (Health Insurance Portability and Accountability Act) and the HITECH Act govern security and privacy requirements for electronic protected health information (ePHI).
Question 5: What is the purpose of a Non-Disclosure Agreement (NDA) in a CREST penetration testing engagement?
- To legally authorize testing activities
- To protect confidential client information discovered during testing (Correct answer)
- To define the payment terms
- To register the engagement with CREST
Correct answer: To protect confidential client information discovered during testing
An NDA ensures that sensitive client information, systems data, and vulnerabilities discovered during testing remain confidential and are not disclosed to unauthorized parties.
Question 6: Which US federal law requires financial institutions to implement safeguards to protect customer information and notify customers of privacy practices?
- SOX
- GLBA (Gramm-Leach-Bliley Act) (Correct answer)
- FERPA
- CAN-SPAM Act
Correct answer: GLBA (Gramm-Leach-Bliley Act)
The Gramm-Leach-Bliley Act requires financial institutions to protect the confidentiality and security of consumers' personal financial information.
Under the US Computer Fraud and Abuse Act (CFAA), what is the primary legal requirement before conducting a penetration test?