PenTest+ Planning & Scoping 5 — Questions and Answers
Question 1: A penetration tester is hired by a subsidiary company. The parent company's systems are reachable from the subsidiary's network. Can the tester legally test the parent company's systems?
- Yes, because they are accessible from the authorized network
- No, unless the parent company has also provided written authorization (Correct answer)
- Yes, if the parent company is mentioned in the subsidiary's contract
- No, unless the tester uses a VPN to access them
Correct answer: No, unless the parent company has also provided written authorization
Authorization to test must come from the entity that owns or is responsible for the systems; reachability from an authorized network does not constitute permission.
Question 2: Which element of the master service agreement (MSA) is most directly relevant to managing liability during a penetration test?
- Payment schedule
- Limitation of liability clauses (Correct answer)
- Tester's certification requirements
- Reporting timelines
Correct answer: Limitation of liability clauses
Limitation of liability clauses cap the financial exposure of both parties in the event that testing causes unintended damage or service disruption.
Question 3: During scoping, the client mentions their environment includes operational technology (OT) and SCADA systems. What is the primary concern?
- OT systems are always easy to exploit
- These systems may be safety-critical and could be permanently damaged by standard testing tools (Correct answer)
- SCADA systems are out of scope by default under all standards
- Testing OT requires no additional planning beyond IT systems
Correct answer: These systems may be safety-critical and could be permanently damaged by standard testing tools
OT/SCADA systems control physical processes and can be irreparably damaged by standard penetration testing tools, requiring specialized methodologies and extreme caution.
Question 4: What is the significance of specifying IP address ranges versus domain names in a penetration test scope document?
- Domain names are always preferred because IPs can change
- IP ranges are more precise but domain names may resolve to shared hosting affecting third parties (Correct answer)
- There is no practical difference between specifying IPs or domain names
- Domain names expand the scope automatically to include all subdomains
Correct answer: IP ranges are more precise but domain names may resolve to shared hosting affecting third parties
Domain names may resolve to shared infrastructure used by multiple organizations, so testing based on IP ranges prevents inadvertent testing of third-party systems sharing the same host.
Question 5: A client requests a 'purple team' exercise rather than a traditional penetration test. How does this affect the planning and scoping phase?
- Purple team exercises require no planning since they are informal
- Scope must include collaboration protocols defining how red and blue teams will share information in real time (Correct answer)
- Purple team exercises are out of scope for PenTest+ certification
- The blue team is excluded from the planning phase entirely
Correct answer: Scope must include collaboration protocols defining how red and blue teams will share information in real time
Purple team exercises require scoping to define information-sharing protocols, collaboration checkpoints, and how the red team's techniques will be communicated to the blue team for training purposes.
Question 6: Why might a penetration tester recommend a phased approach when the client wants to test a very large environment?
- To increase billing opportunities for the tester
- To focus resources on highest-risk areas first and maintain manageable scope within each phase (Correct answer)
- Because regulations require phased testing for all large environments
- To avoid the need for written authorization in later phases
Correct answer: To focus resources on highest-risk areas first and maintain manageable scope within each phase
Phased testing allows methodical coverage of large environments by prioritizing critical assets, keeping each phase's scope manageable, and allowing findings to inform subsequent phases.
Question 7: Which of the following best describes the concept of 'threat modeling' during the planning phase of a penetration test?
- Building a physical model of the target network
- Identifying likely adversaries, their motivations, and the attack vectors most relevant to the target organization (Correct answer)
- Modeling the financial cost of potential breaches
- Creating automated scripts to simulate threats
Correct answer: Identifying likely adversaries, their motivations, and the attack vectors most relevant to the target organization
Threat modeling during planning identifies who might attack the organization, their capabilities, and which attack paths are most realistic, helping focus the penetration test on relevant scenarios.
A penetration tester is hired by a subsidiary company.
The parent company's systems are reachable from the subsidiary's network.
Can the tester legally test the parent company's systems?