Planning and Scoping Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Planning and Scoping flashcards as text
Which of the following BEST describes a 'white-box' penetration test?
Answer: Testing where the tester receives full information including network diagrams, source code, and credentials
White-box testing provides the tester with full knowledge of the environment, enabling thorough coverage and efficient testing.
What is the main reason penetration testers establish a communication plan before starting an engagement?
Answer: To ensure the tester can reach key personnel if critical vulnerabilities are found or if testing causes unintended disruption
A communication plan ensures that critical findings, incidents, or unexpected events can be escalated quickly to the right stakeholders.
During planning, a client specifies that testing must occur only between 2 AM and 5 AM on weekdays. What is this type of restriction called?
Answer: Testing window or maintenance window constraint
Testing windows define the specific time periods during which active testing is authorized to minimize business disruption.
A tester performing reconnaissance discovers the target company uses a cloud provider not mentioned in the scope document. What is the correct action?
Answer: Halt cloud testing and contact the client to clarify whether cloud assets are in scope
Any assets not explicitly listed in the scope require client clarification and additional authorization before testing.
What is the eJPT exam's primary focus when it comes to penetration testing methodology?
Answer: Foundational penetration testing skills including reconnaissance, scanning, exploitation, and reporting
The eJPT certification validates foundational penetration testing skills across the complete testing lifecycle.
Which type of assessment methodology involves the tester being given only the company name and must find everything else independently?
Answer: Black-box assessment
Black-box assessments provide minimal or no initial information, requiring the tester to perform full reconnaissance from scratch.
Why should penetration testers document all their activities with timestamps during an engagement?
Answer: To provide evidence of authorized activity, support incident response if needed, and enable accurate reporting
Timestamped activity logs provide legal protection, support client incident response if systems behave unexpectedly, and form the basis of accurate reporting.