Planning and Scoping Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Planning and Scoping flashcards as text
What is the primary difference between a vulnerability assessment and a penetration test?
Answer: A vulnerability assessment identifies weaknesses while a penetration test actively exploits them to demonstrate real-world impact
Vulnerability assessments identify and classify weaknesses, while penetration tests go further by exploiting vulnerabilities to prove they are truly exploitable.
A company wants to test how well their security team detects and responds to attacks. Which engagement type is MOST appropriate?
Answer: Red team engagement
Red team engagements are specifically designed to test an organization's detection and response capabilities by simulating realistic adversary behavior.
Which of the following items should be included in the initial kickoff meeting for a penetration testing engagement?
Answer: Confirmation of scope, testing windows, emergency contacts, and escalation procedures
The kickoff meeting should establish mutual understanding of scope boundaries, authorized timeframes, key contacts, and escalation procedures before testing begins.
Why is it important for a penetration tester to understand the client's compliance requirements (e.g., PCI-DSS, HIPAA) during the planning phase?
Answer: To tailor the testing methodology and report format to meet specific compliance standards and audit requirements
Compliance frameworks often dictate specific testing requirements, scope, and reporting formats that must be followed for the results to satisfy auditors.
During planning, the client provides a subnet that includes a hospital patient monitoring system. What should the tester do?
Answer: Flag it immediately and discuss with the client whether to exclude critical medical systems from scope due to safety risks
Critical safety systems like medical equipment should be explicitly discussed and likely excluded from scope to prevent risk to human life.
What does the term 'OSINT' stand for and how is it used in penetration test planning?
Answer: Open Source Intelligence — used to gather publicly available information about the target before active testing
OSINT involves collecting and analyzing publicly available information to build knowledge about the target without direct interaction.
Which of the following BEST represents the concept of 'minimum footprint' during a penetration test?
Answer: Limiting actions to only what is necessary to demonstrate the vulnerability, avoiding unnecessary system changes or data access
Minimum footprint means testers should only do what is necessary to prove a vulnerability exists, minimizing disruption and avoiding unnecessary data exposure.