eJPT Planning and Scoping 3 — Questions and Answers
Question 1: Which of the following BEST describes a 'white-box' penetration test?
- Testing conducted without any documentation or prior information
- Testing where the tester receives full information including network diagrams, source code, and credentials (Correct answer)
- Testing where only the IP address range is provided
- Testing conducted from inside the organization's network
Correct answer: Testing where the tester receives full information including network diagrams, source code, and credentials
White-box testing provides the tester with full knowledge of the environment, enabling thorough coverage and efficient testing.
Question 2: What is the main reason penetration testers establish a communication plan before starting an engagement?
- To schedule weekly status meetings with the client
- To ensure the tester can reach key personnel if critical vulnerabilities are found or if testing causes unintended disruption (Correct answer)
- To keep the client updated on tool selection
- To document the tester's working hours
Correct answer: To ensure the tester can reach key personnel if critical vulnerabilities are found or if testing causes unintended disruption
A communication plan ensures that critical findings, incidents, or unexpected events can be escalated quickly to the right stakeholders.
Question 3: During planning, a client specifies that testing must occur only between 2 AM and 5 AM on weekdays. What is this type of restriction called?
- Scope limitation
- Testing window or maintenance window constraint (Correct answer)
- Black-box restriction
- Compliance boundary
Correct answer: Testing window or maintenance window constraint
Testing windows define the specific time periods during which active testing is authorized to minimize business disruption.
Question 4: A tester performing reconnaissance discovers the target company uses a cloud provider not mentioned in the scope document. What is the correct action?
- Proceed with testing the cloud infrastructure since it belongs to the client
- Halt cloud testing and contact the client to clarify whether cloud assets are in scope (Correct answer)
- Skip the cloud assets entirely and note them as out of scope
- Test the cloud assets and include findings in an appendix
Correct answer: Halt cloud testing and contact the client to clarify whether cloud assets are in scope
Any assets not explicitly listed in the scope require client clarification and additional authorization before testing.
Question 5: What is the eJPT exam's primary focus when it comes to penetration testing methodology?
- Advanced exploit development and zero-day research
- Foundational penetration testing skills including reconnaissance, scanning, exploitation, and reporting (Correct answer)
- Social engineering and physical security assessments
- Red team operations and adversary simulation
Correct answer: Foundational penetration testing skills including reconnaissance, scanning, exploitation, and reporting
The eJPT certification validates foundational penetration testing skills across the complete testing lifecycle.
Question 6: Which type of assessment methodology involves the tester being given only the company name and must find everything else independently?
- White-box assessment
- Crystal-box assessment
- Black-box assessment (Correct answer)
- Gray-box assessment
Correct answer: Black-box assessment
Black-box assessments provide minimal or no initial information, requiring the tester to perform full reconnaissance from scratch.
Question 7: Why should penetration testers document all their activities with timestamps during an engagement?
- To bill the client accurately for time spent
- To provide evidence of authorized activity, support incident response if needed, and enable accurate reporting (Correct answer)
- To track tool performance and scan speed
- To comply with ISO 27001 requirements
Correct answer: To provide evidence of authorized activity, support incident response if needed, and enable accurate reporting
Timestamped activity logs provide legal protection, support client incident response if systems behave unexpectedly, and form the basis of accurate reporting.
Which of the following BEST describes a 'white-box' penetration test?