Given a client scenario, identify the governing document, correct testing methodology, and whether authorization covers every target. The single most important thing: never test an asset without documented, written permission from the party that owns or hosts it.
Start practicing
Pen Test Planning — choose a session length
Free · No account required
Domain overview
The Pen Test Planning domain covers scoping, legal authorization, and engagement design before any exploitation begins. GPEN questions present client scenarios and ask you to select the correct document, testing methodology, or escalation path. Expect to reason about Rules of Engagement, authorization boundaries, third-party hosting, and how target knowledge shapes test design and reporting.
Exam objectives
Rules of Engagement defining scope, authorized targets, time windows, and emergency contacts
Black-box, gray-box, and white-box methodologies and the target knowledge each provides
Written authorization and third-party cloud hosting consent before testing external assets
Scoping statements of work that bound IP ranges, applications, and testing limitations
Treating a verbal go-ahead or email as sufficient authorization when written permission from the asset owner is required
Confusing gray-box (partial knowledge) with black-box (zero knowledge) when the scenario describes credentials or documentation provided
Ignoring third-party cloud provider restrictions and testing hosted assets without the provider's written consent
Click any question to see the full explanation and answer options, or start a focused practice session above.
An enterprise client insists on a blind 'black-box' penetration test where the testing team receives zero prior knowledge regarding network architecture, IP ranges, or applications. However, the client's primary objective is to thoroughly test deep-seated business logic vulnerabilities within a critical custom web application. Why is this planning approach fundamentally misaligned with the client's stated objective?
2During the scoping phase of a penetration test for a global e-commerce client, you identify that the client uses a cloud-based Content Delivery Network (CDN) to host static assets. Which action is the most critical for ensuring the engagement remains within the Rules of Engagement (RoE)?
3You are drafting the Rules of Engagement for an internal penetration test. Which TWO of the following items are considered mandatory for the 'Communication Plan' section?
4Refer to the exhibit. You are performing a penetration test based on this policy. You discover an unpatched SQL injection vulnerability on 192.168.10.20 that could be used to trigger a database lock-up. What is the most appropriate course of action?
5Which document is primarily responsible for defining the 'Rules of Engagement' (RoE) in a penetration testing project?
6During planning, a client requests that you use a specific automated scanner that is known to produce false positives and potential system instability. What is the most professional way to handle this request?
7When defining the 'Scope' for a penetration test, which THREE factors are critical to document to ensure the engagement is legally and operationally sound?
8A client asks for an 'unannounced' penetration test to test their incident response team. What is the most important preparatory step before commencing this exercise?
9Refer to the exhibit. You are currently at 17:15. You have just identified a critical, easily exploitable vulnerability on 10.1.1.20. What is the correct next step?
10Which of the following best describes the 'Gray-box' testing methodology?
11What is the primary purpose of the 'Scope' section in the Rules of Engagement?
12If a penetration tester discovers a vulnerability that could compromise a third-party hosted service during an engagement, what is the correct professional responsibility?
13When planning for an engagement involving sensitive data, which TWO of the following must be included in the data handling plan?
14You are finalizing the Rules of Engagement (RoE) for a penetration test of a regional hospital network. The client's legal counsel requires that any testing activity be immediately suspended if a life-safety system is affected. Which element should you add to the RoE to satisfy this requirement?
15A financial services client engages you for an external penetration test and wants contractual protection before testing begins. Which TWO items belong in a master services agreement or statement of work to limit the firm's legal exposure while authorizing the work? (Choose two.)
16During planning for a penetration test, the client states the goal is to evaluate how well the security operations center detects and responds to attacker activity. Which engagement type best aligns with this objective?
17You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to test a new patient portal hosted on AWS. During the kickoff meeting, the client's legal team asks how you will handle any protected health information (PHI) that you might encounter. Which of the following is the most appropriate action to take before testing begins?
18You are planning a penetration test for a financial institution that operates a large mainframe environment. The client wants to ensure that the test does not disrupt critical batch processing jobs. Which TWO of the following are the MOST important items to include in the Rules of Engagement (RoE) to address this concern? (Choose two.)
19You are the lead penetration tester for a financial services client. During the scoping meeting, the client states they want to test their external perimeter but are concerned about accidental disruption to production trading systems. They ask you to propose a testing approach that minimizes operational risk while still validating exploitable vulnerabilities. Which of the following is the MOST appropriate recommendation?
20A client asks you to perform a penetration test on their internal network. During the planning phase, they provide you with a list of IP addresses and ask you to sign a document that limits your testing to those addresses. Which of the following best describes the purpose of this document?
21You are the lead penetration tester for an engagement at a regional bank. The client's legal team has approved testing of their external IP range, but the Statement of Work does not mention the third-party core banking platform hosted by a vendor on a shared subnet. During reconnaissance, you discover that one of the client's external IPs routes directly into the vendor's shared environment. What is the MOST appropriate action before conducting any exploitation?
22You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to ensure that any protected health information (PHI) accessed during testing is handled securely. Which of the following is the MOST critical element to include in the data handling plan?
23You are planning a penetration test for a client that has a hybrid cloud environment. The client's security team wants to ensure that the test does not violate the shared responsibility model of their cloud provider. Which of the following should you do FIRST to align the test with the cloud provider's policies?
24A healthcare client hires your team for an internal penetration test. During the kickoff meeting, the client's compliance officer asks which document formally defines the specific systems, time windows, and testing techniques that are authorized for the engagement. Which document should you reference?
25You are drafting the Rules of Engagement (RoE) for a penetration test of a client's internal network. The client wants to ensure that the engagement is legally sound and that all parties understand their responsibilities. Which TWO of the following items are essential to include in the RoE? (Choose two.)
26During the planning phase of a penetration test for a multinational corporation, you discover that the client's legal department requires all testing activities to comply with the laws of each country where their offices are located. The client has offices in Germany, Brazil, and Japan. Which of the following is the MOST important consideration when planning the engagement?
27You are planning an external penetration test for a financial services firm. The client's legal team wants assurance that the engagement can be defended if law enforcement or regulators inquire about the testing. Which TWO of the following should be included in the Rules of Engagement to provide this assurance? (Choose two.)
28A client asks you to perform a penetration test on their web application. During the planning phase, they mention that the application is hosted on a third-party cloud provider and they do not have written permission from the provider to test the underlying infrastructure. What is the MOST appropriate action?
29During a penetration test for a multinational retailer, you discover that a legacy internal application in scope contains a hardcoded credential that also grants access to a payment processing system the client explicitly excluded from testing. You have not yet used the credential. What is the MOST appropriate course of action?
30You are planning a penetration test for a client with a large wireless network. The client wants to assess the security of their WPA3-Enterprise deployment. Which of the following should be included in the Rules of Engagement to address the risk of disrupting legitimate wireless users?
31A software-as-a-service provider engages your team for a penetration test of its production environment. The client wants testing to occur during business hours so its engineers can observe. Which planning consideration is MOST important to address in the Rules of Engagement before testing begins?
Given a client scenario, identify the governing document, correct testing methodology, and whether authorization covers every target. The single most important thing: never test an asset without documented, written permission from the party that owns or hosts it.
The Courseiva GPEN question bank contains 31 questions in the Pen Test Planning domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Pen Test Planning domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included