Engagement planning, scoping rules of engagement, and legal considerations tested on the CompTIA PenTest+ exam.
34 cards · basic cards · AI-written, checked twice. Edit anything.
- What is the primary purpose of Rules of Engagement in a penetration test?
- To establish legal boundaries, authorized testing activities, and limitations between the tester and client before work begins.
- What must a penetration test scope definition include?
- Systems, networks, applications, and physical locations to be tested, plus explicit out-of-scope items.
- What document outlines the testing timeline and specific testing windows?
- Statement of Work (SOW).
- What is an out-of-scope item in penetration testing?
- A system, network, application, or activity explicitly excluded from the engagement that the tester will not target.
- Why is client authorization required before beginning a penetration test?
- To ensure the testing is legal, legitimate, and protects both parties from liability for activities that would otherwise appear to be unauthorized attacks.
- What is a Non-Disclosure Agreement (NDA) used for in penetration testing?
- To protect the confidentiality of sensitive information discovered during testing and prevent unauthorized disclosure of findings.
- What does a Master Service Agreement (MSA) establish in a penetration testing engagement?
- The overall terms, conditions, and legal framework governing the business relationship between the tester and client.
- What key information must be included in a Statement of Work (SOW)?
- Testing scope, timeline, deliverables, testing methodology, schedule, costs, and specific objectives.
- What is the purpose of establishing a Rules of Engagement (ROE) document?
- To define what testing activities are allowed, testing restrictions, client contact procedures, and incident response protocols.
- What should be defined regarding client contact in a penetration test engagement?
- Emergency contact procedures, escalation paths, communication frequency, and authorized personnel to contact.
- What does scope creep mean in penetration testing and why is it problematic?
- When testing expands beyond the agreed scope, consuming extra resources and potentially violating the Rules of Engagement or client authorization.
- What testing windows must be defined in the Rules of Engagement?
- Specific dates, times, and durations when testing is authorized, including any restrictions on after-hours or critical-time testing.
- Why is establishing baseline security posture important before a penetration test?
- To document existing security controls and verify the client environment has not been altered, enabling accurate assessment of tester impact.
- What is a critical asset in the context of penetration testing scope?
- A system or service essential to business operations that may have testing restrictions or require special approval before targeting.
- What must be defined regarding data handling during a penetration test?
- How sensitive data encountered will be protected, whether it can be accessed, retention requirements, and destruction procedures.