PenTest+ Planning & Scoping 4 — Questions and Answers
Question 1: During scoping, a client requests a penetration test of their mobile banking application. Which additional consideration is unique to mobile application testing?
- Testing must be done only on physical devices
- App store policies and device OS versions must be considered in scope definition (Correct answer)
- Mobile tests require no rules of engagement
- Only iOS devices need to be tested
Correct answer: App store policies and device OS versions must be considered in scope definition
Mobile app testing scope must account for different OS versions (iOS/Android), device types, and app store distribution channels that affect the attack surface.
Question 2: A red team exercise differs from a standard penetration test primarily in that it:
- Uses only automated scanning tools
- Simulates a targeted, realistic adversary with defined objectives over an extended period (Correct answer)
- Is limited to external network testing only
- Does not require written authorization
Correct answer: Simulates a targeted, realistic adversary with defined objectives over an extended period
Red team exercises emulate advanced persistent threat actors pursuing specific objectives (e.g., data exfiltration) over weeks or months, unlike point-in-time penetration tests.
Question 3: Which of the following is a key reason to include third-party service providers in the scoping discussion of a penetration test?
- Third-party providers always have more vulnerabilities
- Testing systems owned by third parties may require separate authorization (Correct answer)
- Third-party systems are always out of scope
- Providers must perform their own portion of the test
Correct answer: Testing systems owned by third parties may require separate authorization
Third-party owned infrastructure (SaaS, cloud providers, MSPs) requires separate authorization from those providers before testing, even if the client uses the service.
Question 4: What is the purpose of defining 'success criteria' during the planning phase of a penetration test?
- To guarantee the tester will find vulnerabilities
- To establish measurable objectives that determine when the engagement goals are met (Correct answer)
- To limit the number of hours billed
- To define which tools the tester is required to use
Correct answer: To establish measurable objectives that determine when the engagement goals are met
Success criteria provide clear, agreed-upon objectives (e.g., 'obtain domain admin credentials' or 'access PII database') so both parties know what constitutes a completed engagement.
Question 5: A penetration tester is asked to perform a physical security assessment as part of a broader engagement. Which additional authorization consideration applies?
- Physical testing requires no additional authorization if logical systems are in scope
- Written permission specific to physical access attempts must be obtained (Correct answer)
- Physical testing is always illegal and should be refused
- Only the IT department needs to authorize physical testing
Correct answer: Written permission specific to physical access attempts must be obtained
Physical penetration testing involves entering facilities or bypassing physical controls, which requires explicit written authorization separate from network testing permission.
Question 6: When assessing scope for a web application penetration test, why is it important to identify the application's technology stack in advance?
- The technology stack determines the price of the engagement
- Different technologies have unique vulnerabilities and require specific testing methodologies (Correct answer)
- Knowing the stack allows the tester to skip reconnaissance
- The stack determines which regulatory framework applies
Correct answer: Different technologies have unique vulnerabilities and require specific testing methodologies
Understanding the technology stack (e.g., PHP, Java, .NET, frameworks) helps identify relevant vulnerability classes and ensures appropriate testing tools and techniques are included in scope.
Question 7: What is 'scope creep' in the context of a penetration testing engagement, and why is it problematic?
- When the tester discovers more vulnerabilities than expected
- Unauthorized expansion of testing beyond the agreed boundaries (Correct answer)
- When the engagement takes longer than planned
- When the client adds more testers to the project
Correct answer: Unauthorized expansion of testing beyond the agreed boundaries
Scope creep occurs when testing expands beyond documented boundaries without authorization, creating legal exposure and potentially impacting systems the client did not intend to include.
During scoping, a client requests a penetration test of their mobile banking application.
Which additional consideration is unique to mobile application testing?