FlashKeepers

CompTIA PenTest+ · CompTIA PenTest+

CompTIA PenTest+ Planning and Scoping

Engagement planning, scoping rules of engagement, and legal considerations tested on the CompTIA PenTest+ exam.

34 cards · basic cards · AI-written, checked twice. Edit anything.

Study this set free Look inside first Get FlashKeepers for iPhone
What is the primary purpose of Rules of Engagement in a penetration test?
To establish legal boundaries, authorized testing activities, and limitations between the tester and client before work begins.
What must a penetration test scope definition include?
Systems, networks, applications, and physical locations to be tested, plus explicit out-of-scope items.
What document outlines the testing timeline and specific testing windows?
Statement of Work (SOW).
What is an out-of-scope item in penetration testing?
A system, network, application, or activity explicitly excluded from the engagement that the tester will not target.
Why is client authorization required before beginning a penetration test?
To ensure the testing is legal, legitimate, and protects both parties from liability for activities that would otherwise appear to be unauthorized attacks.
What is a Non-Disclosure Agreement (NDA) used for in penetration testing?
To protect the confidentiality of sensitive information discovered during testing and prevent unauthorized disclosure of findings.
What does a Master Service Agreement (MSA) establish in a penetration testing engagement?
The overall terms, conditions, and legal framework governing the business relationship between the tester and client.
What key information must be included in a Statement of Work (SOW)?
Testing scope, timeline, deliverables, testing methodology, schedule, costs, and specific objectives.
What is the purpose of establishing a Rules of Engagement (ROE) document?
To define what testing activities are allowed, testing restrictions, client contact procedures, and incident response protocols.
What should be defined regarding client contact in a penetration test engagement?
Emergency contact procedures, escalation paths, communication frequency, and authorized personnel to contact.
What does scope creep mean in penetration testing and why is it problematic?
When testing expands beyond the agreed scope, consuming extra resources and potentially violating the Rules of Engagement or client authorization.
What testing windows must be defined in the Rules of Engagement?
Specific dates, times, and durations when testing is authorized, including any restrictions on after-hours or critical-time testing.
Why is establishing baseline security posture important before a penetration test?
To document existing security controls and verify the client environment has not been altered, enabling accurate assessment of tester impact.
What is a critical asset in the context of penetration testing scope?
A system or service essential to business operations that may have testing restrictions or require special approval before targeting.
What must be defined regarding data handling during a penetration test?
How sensitive data encountered will be protected, whether it can be accessed, retention requirements, and destruction procedures.

19 more cards in the app