PenTest+ Planning & Scoping 2 — Questions and Answers
Question 1: A penetration tester receives a statement of work that prohibits testing production systems during business hours. What type of constraint is this?
- Legal constraint
- Technical constraint
- Environmental constraint (Correct answer)
- Regulatory constraint
Correct answer: Environmental constraint
Environmental constraints define operational boundaries such as time windows, system availability, and business impact limitations.
Question 2: Which document formally authorizes a penetration tester to perform security assessments and protects them from legal liability?
- Non-disclosure agreement
- Master service agreement
- Rules of engagement (Correct answer)
- Statement of work
Correct answer: Rules of engagement
The rules of engagement (ROE) document formally authorizes testing activities and defines boundaries, providing legal protection for the tester.
Question 3: A client wants a penetration test but is concerned about sensitive data exposure during the test. Which scoping consideration addresses this?
- Defining target IP ranges
- Establishing data handling procedures (Correct answer)
- Setting test time windows
- Identifying third-party dependencies
Correct answer: Establishing data handling procedures
Data handling procedures ensure that sensitive information encountered during testing is protected, stored securely, and not improperly disclosed.
Question 4: When scoping a penetration test for a company that uses AWS infrastructure, what is the most important additional step compared to testing on-premises systems?
- Obtain written permission from AWS (Correct answer)
- Increase the test duration
- Use only passive reconnaissance
- Notify local law enforcement
Correct answer: Obtain written permission from AWS
Cloud providers like AWS have their own penetration testing policies and require customers to obtain permission before testing cloud-hosted resources.
Question 5: A penetration tester discovers a critical zero-day vulnerability during an engagement. What should they do first according to rules of engagement best practices?
- Exploit the vulnerability to prove its impact
- Publish the finding immediately
- Notify the client through the agreed-upon communication channel (Correct answer)
- Report it to a vulnerability database
Correct answer: Notify the client through the agreed-upon communication channel
The rules of engagement typically define escalation procedures for critical findings; notifying the client through agreed channels ensures proper handling.
Question 6: What is the primary purpose of defining the target audience in a penetration test report?
- To limit the number of people who read the report
- To tailor technical depth and language to the reader's expertise (Correct answer)
- To determine which vulnerabilities to include
- To set the price of the engagement
Correct answer: To tailor technical depth and language to the reader's expertise
Understanding the target audience allows the report to be written at an appropriate technical level, making findings actionable for executives or technical staff.
Question 7: During pre-engagement scoping, a client states 'test everything.' What should the penetration tester do?
- Begin testing immediately with maximum scope
- Require the client to define a specific, documented scope (Correct answer)
- Test only publicly accessible systems
- Decline the engagement due to vague scope
Correct answer: Require the client to define a specific, documented scope
Vague scope definitions create legal and operational risk; the tester must work with the client to document specific targets, boundaries, and exclusions.
A penetration tester receives a statement of work that prohibits testing production systems during business hours.
What type of constraint is this?