Planning and Scoping Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Planning and Scoping flashcards as text
A client asks you to test their web application but explicitly excludes the database server from scope. During testing, you discover a SQL injection that likely affects the database. What should you do?
Answer: Document the finding and immediately notify the client about the out-of-scope risk
When you discover a vulnerability that affects out-of-scope systems, you must stop and notify the client so they can decide how to proceed.
What is the primary purpose of defining Rules of Engagement (RoE) in a penetration testing engagement?
Answer: To outline the legal, technical, and operational boundaries for the test
Rules of Engagement define the boundaries, permissions, and constraints under which the penetration test will be conducted.
During scoping, a client wants to include a third-party SaaS platform they use. What must you verify before including it?
Answer: That the client has written authorization from the third-party vendor to test their platform
Third-party systems require explicit written authorization from their owners before they can be included in a penetration test scope.
Which document type formally authorizes a penetration tester to perform activities that would otherwise be considered illegal?
Answer: Get-Out-of-Jail-Free letter / Authorization letter
A get-out-of-jail letter or authorization letter provides documented proof that the tester is legally authorized to conduct the engagement.
What does 'threat modeling' during the planning phase of a pentest primarily help identify?
Answer: The likely attackers, their motivations, and the most relevant attack scenarios for the target
Threat modeling helps prioritize testing efforts by identifying realistic adversaries and the attack paths most relevant to the organization.
A penetration tester is conducting a black-box assessment. Which of the following BEST describes this approach?
Answer: The tester simulates an external attacker with no prior knowledge of the target
Black-box testing simulates an external attacker who has no prior knowledge of the target environment.
When establishing scope, why is it important to specify the exact IP ranges and domain names in writing?
Answer: To prevent accidental testing of systems outside the authorized scope and protect the tester legally
Precisely defined scope in writing protects both the client and tester by clearly establishing which systems are authorized for testing.