eJPT Planning and Scoping 5 — Questions and Answers
Question 1: What is the primary difference between a vulnerability assessment and a penetration test?
- A vulnerability assessment is more expensive than a penetration test
- A vulnerability assessment identifies weaknesses while a penetration test actively exploits them to demonstrate real-world impact (Correct answer)
- A penetration test only uses automated tools while a vulnerability assessment is manual
- A vulnerability assessment requires more time to complete than a penetration test
Correct answer: A vulnerability assessment identifies weaknesses while a penetration test actively exploits them to demonstrate real-world impact
Vulnerability assessments identify and classify weaknesses, while penetration tests go further by exploiting vulnerabilities to prove they are truly exploitable.
Question 2: A company wants to test how well their security team detects and responds to attacks. Which engagement type is MOST appropriate?
- Vulnerability assessment
- Compliance audit
- Red team engagement (Correct answer)
- White-box penetration test
Correct answer: Red team engagement
Red team engagements are specifically designed to test an organization's detection and response capabilities by simulating realistic adversary behavior.
Question 3: Which of the following items should be included in the initial kickoff meeting for a penetration testing engagement?
- A list of all vulnerabilities the tester expects to find
- Confirmation of scope, testing windows, emergency contacts, and escalation procedures (Correct answer)
- The tester's preferred exploitation frameworks
- The client's full network topology diagram
Correct answer: Confirmation of scope, testing windows, emergency contacts, and escalation procedures
The kickoff meeting should establish mutual understanding of scope boundaries, authorized timeframes, key contacts, and escalation procedures before testing begins.
Question 4: Why is it important for a penetration tester to understand the client's compliance requirements (e.g., PCI-DSS, HIPAA) during the planning phase?
- To determine how much to charge for the engagement
- To tailor the testing methodology and report format to meet specific compliance standards and audit requirements (Correct answer)
- To avoid testing any systems that fall under compliance scope
- To ensure the tester is certified in that compliance framework
Correct answer: To tailor the testing methodology and report format to meet specific compliance standards and audit requirements
Compliance frameworks often dictate specific testing requirements, scope, and reporting formats that must be followed for the results to satisfy auditors.
Question 5: During planning, the client provides a subnet that includes a hospital patient monitoring system. What should the tester do?
- Include it in scope since the client authorized the subnet
- Flag it immediately and discuss with the client whether to exclude critical medical systems from scope due to safety risks (Correct answer)
- Test it only during off-peak hours to minimize risk
- Test it with passive techniques only
Correct answer: Flag it immediately and discuss with the client whether to exclude critical medical systems from scope due to safety risks
Critical safety systems like medical equipment should be explicitly discussed and likely excluded from scope to prevent risk to human life.
Question 6: What does the term 'OSINT' stand for and how is it used in penetration test planning?
- Offensive Security Intelligence Testing — used to automate exploits
- Open Source Intelligence — used to gather publicly available information about the target before active testing (Correct answer)
- Operational Security Internal Testing — used for internal assessments only
- Online System Integrity Testing — used to verify system uptime
Correct answer: Open Source Intelligence — used to gather publicly available information about the target before active testing
OSINT involves collecting and analyzing publicly available information to build knowledge about the target without direct interaction.
Question 7: Which of the following BEST represents the concept of 'minimum footprint' during a penetration test?
- Using the smallest possible number of scanning tools
- Limiting actions to only what is necessary to demonstrate the vulnerability, avoiding unnecessary system changes or data access (Correct answer)
- Keeping the engagement duration as short as possible
- Restricting testing to a single subnet
Correct answer: Limiting actions to only what is necessary to demonstrate the vulnerability, avoiding unnecessary system changes or data access
Minimum footprint means testers should only do what is necessary to prove a vulnerability exists, minimizing disruption and avoiding unnecessary data exposure.
What is the primary difference between a vulnerability assessment and a penetration test?