Courseiva

CCNA Engagement Management Questions

62 questions · Engagement Management · All types, answers revealed

1
MCQmedium

A penetration tester is planning a social engineering engagement targeting employees of a client. The client requests that only non-managerial staff be tested. Which scoping consideration is most directly affected by this request?

A.IP address range
B.Production vs. staging
C.Third-party services
D.Personnel scope
AnswerD

Personnel scope explicitly enumerates which individuals or employee groups—such as executives, IT administrators, or finance staff—are authorized targets for social engineering. It also dictates permissible attack vectors like email phishing, phone vishing, or physical tailgating, while ensuring the engagement remains within agreed ethical and legal boundaries. Without a defined personnel scope, testing could inadvertently target non-consenting individuals, violating rules of engagement and creating legal liability.

Why this answer

Personnel scope determines which individuals or groups are targeted in social engineering tests.

2
MCQhard

During a social engineering engagement, a tester is authorized to target employees via email phishing. However, the tester accidentally sends a phishing email to a contractor who is not listed in the personnel scope. The contractor reports the email to the client's security team, causing an internal investigation. Which of the following best describes the tester's mistake?

A.Breach of the Non-Disclosure Agreement
B.Failure to follow the Rules of Engagement
C.Mishandling of discovered criminal activity
D.Violation of the Computer Fraud and Abuse Act (CFAA)
AnswerB

The Rules of Engagement (RoE) explicitly define the authorized targets, including personnel, systems, and timeframes, and any deviation from those parameters is a scope violation. By directing phishing emails to out-of-scope individuals, the tester exceeded the documented authorization, which is precisely a failure to follow the RoE. This can invalidate the engagement's legal cover and expose the client or tester to liability.

Why this answer

Personnel scope must be clearly defined; the tester failed to adhere to the scoping requirements for social engineering.

3
MCQmedium

Which of the following is the primary purpose of a get-out-of-jail letter in a penetration testing engagement?

A.To protect the client from legal liability
B.To document emergency contacts
C.To outline the scope of the test
D.To authorize the tester to perform testing activities and avoid prosecution
AnswerD

This letter, commonly known as a 'get-out-of-jail-free' letter, explicitly authorizes the penetration tester to perform activities that would otherwise violate computer fraud and abuse laws. It provides prima facie evidence of consent from the client, protecting the tester from criminal prosecution for unauthorized access. Without this authorization, even a legitimate security test could be deemed illegal, so the letter is the primary legal safeguard for the tester.

Why this answer

The get-out-of-jail letter provides legal authorization for the tester to perform activities that might otherwise be considered illegal, such as scanning or exploitation.

4
Multi-Selectmedium

A penetration testing company is scoping a test for a client. The client wants to ensure that testing does not impact production systems. Which TWO of the following are appropriate scoping considerations? (Select TWO.)

Select 2 answers
A.Testing on a staging environment
B.Including all third-party services
C.Allowing unlimited testing hours
D.Testing all IP addresses in the organization
E.Defining specific test windows
AnswersA, E

Staging environments replicate production with controlled data and no live users, so security tests can safely simulate attacks without impacting business operations. They allow for thorough testing of vulnerabilities like injection or authentication flaws in a realistic but isolated setting. Scoping to a staging environment reduces legal and operational risks while still validating security controls effectively.

Why this answer

Option A is correct because testing on a staging environment allows the penetration testers to exercise the same application and infrastructure components without touching live production systems, directly satisfying the client's requirement that production not be impacted. Option E is correct because defining specific test windows constrains testing to agreed low-risk periods, which limits the chance that active scanning, exploitation, or traffic spikes will disrupt production services and gives the client control over when impact is possible. Option B is not appropriate because including all third-party services expands scope beyond the client's control and can affect external production systems the client does not own.

Option C is not appropriate because allowing unlimited testing hours removes the scheduling control needed to protect production during peak or business-critical times. Option D is not appropriate because testing all IP addresses in the organization would include production hosts, contradicting the goal of avoiding production impact.

Exam trap

The trap here is that candidates may confuse 'defining specific test windows' with a scheduling detail rather than a scoping control, but it directly prevents testing during production peak hours, thus protecting production systems from impact.

5
MCQmedium

During the pre-engagement phase, a penetration tester and the client agree on the specific IP ranges to be tested, testing windows, and what constitutes an emergency stop condition. Which document typically contains these details?

A.Non-Disclosure Agreement (NDA)
B.Get-out-of-jail letter
C.Rules of Engagement (RoE)
D.Statement of Work (SOW)
AnswerC

The Rules of Engagement document records the agreed scope, IP ranges, testing windows and emergency stop conditions between tester and client. It satisfies the pre-engagement requirement by formalising these authorisation and boundary details before testing begins, distinct from the statement of work or NDA.

Why this answer

The Rules of Engagement (RoE) document is specifically designed to define the scope, authorization, and constraints of a penetration test, including target IP ranges, testing windows, and emergency stop conditions. This ensures both the tester and client have a clear, legally binding agreement on how the test will be conducted, preventing misunderstandings or unauthorized actions.

Exam trap

Candidates often confuse the SOW with the RoE. While the SOW covers high-level deliverables and objectives, the RoE specifies the precise operational details, such as the IP ranges to test, testing windows, and emergency stop conditions, as described in this question.

How to eliminate wrong answers

Option A is wrong because a Non-Disclosure Agreement (NDA) is a legal contract that protects confidential information shared between parties, not operational details like IP ranges or testing windows. Option B is wrong because a get-out-of-jail letter is an authorization document that protects the tester from legal liability during testing, but it does not contain scoping details such as IP ranges or testing schedules. Option D is wrong because a Statement of Work (SOW) outlines high-level project deliverables, timelines, and costs, but it typically does not include the granular operational constraints like emergency stop conditions or specific IP ranges, which are reserved for the RoE.

6
MCQeasy

A company hires a penetration testing firm to simulate the tactics, techniques, and procedures of a real adversary. The engagement includes attempting to achieve specific objectives without being detected. This type of engagement is best described as:

A.Network penetration test
B.Web application penetration test
C.Social engineering engagement
D.Red team exercise
AnswerD

A red team exercise is an objective-based, adversarial simulation that mimics the tactics, techniques, and procedures (TTPs) of a specific real-world threat actor, with rules of engagement allowing stealth, creativity, and a kill-chain approach. It tests not just the existence of vulnerabilities but also the blue team's detection, response, and recovery capabilities by conducting a realistic attack lifecycle—reconnaissance, initial compromise, lateral movement, privilege escalation, and impact or exfiltration. Unlike a standard pen test, a red team engagement is often conducted without the defensive team being forewarned, and it succeeds only if it achieves a predefined business objective without being caught, making it the closest simulation of a genuine attack.

Why this answer

A red team exercise is an adversary simulation that aims to test detection and response capabilities.

7
Multi-Selectmedium

A penetration tester is scoping a web application penetration test. The client wants to include a third-party API that processes payments. Which TWO are appropriate considerations?

Select 2 answers
A.Assume the API is secure because it is a well-known provider
B.Test only the client's code and ignore the API entirely
C.Obtain written permission from the third-party provider before testing
D.Include the API in scope without permission because it is critical to the application
E.Document the API as out-of-scope if permission is not granted
AnswersC, E

Written permission from the third-party provider is the only legally defensible basis for actively testing their API, as it establishes an authorization boundary that protects both the tester and the client from claims of unauthorized access under laws like the Computer Fraud and Abuse Act (CFAA) and similar regulations. This permission should explicitly define the testing scope, allowed techniques, and time windows, and it should ideally be obtained through the provider's official pen-testing authorization process or by adding the tester to the client's contract with the provider. Without such written authorization, even well-intentioned security testing can be construed as malicious activity, so obtaining this document is a non-negotiable prerequisite before any API testing begins.

Why this answer

Option C is correct because testing a third-party payment API without the provider's explicit written authorization is unauthorized access, regardless of the client's ownership of the application; the tester must obtain permission from the API provider (or verify the client has it) before sending any test traffic to that API. Option E is correct because if the provider does not grant permission, the API must be formally documented as out-of-scope in the rules of engagement and scope statement, so the tester avoids any unauthorized testing while still delivering a clear, defensible report. Option A is wrong because assuming a well-known provider is secure is an unfounded trust assumption that ignores the need for verification and authorization.

Option B is wrong because ignoring the API entirely may leave critical integration risks (authentication, data flow, error handling) untested and unassessed. Option D is wrong because criticality to the application never overrides the legal and ethical requirement for explicit permission before testing third-party systems.

Exam trap

The trap here is that candidates may assume a well-known API is inherently secure (Option A) or that testing only the client's code is sufficient (Option B), overlooking the legal necessity of permission and the risk of integration flaws.

8
MCQhard

A penetration tester is conducting a grey box test on a web application. During the test, the tester discovers that the application is hosted on a cloud infrastructure that belongs to a third-party provider. The client did not mention this provider in the scope. What is the best course of action regarding testing this infrastructure?

A.Add the cloud provider to the scope without notifying the client
B.Stop testing the cloud infrastructure and notify the client
C.Continue testing because the application is owned by the client
D.Obtain verbal permission from the cloud provider and proceed
AnswerB

The correct action is to immediately halt all testing against the cloud-infrastructure components that fall outside the client-authorized scope. Because the infrastructure is owned and operated by the cloud provider as a third party, continuing against it without authorization could constitute unauthorized access under laws like the CFAA or the Computer Misuse Act, and the tester must notify the client so the client can formally amend the scope or obtain written permission from the provider.

Why this answer

Testing third-party infrastructure without permission is illegal and violates the rules of engagement. The tester should stop testing that part and inform the client.

9
MCQmedium

A company wants to simulate a real-world attack scenario where the penetration tester has no prior knowledge of the environment and must act as an external threat actor. However, the tester is allowed to use social engineering to gain initial access. Which type of engagement is most appropriate?

A.Red team exercise
B.Network penetration test
C.Wireless penetration test
D.Web application penetration test
AnswerA

A red team exercise is a full-scope, objective-based simulation that mimics a real adversary's tactics, techniques, and procedures (TTPs), including social engineering, physical access, email phishing, and exploitation. Unlike a single-vector assessment, it is designed to test the organization's overall security posture — people, processes, and technology — by stealthily moving toward a defined goal, such as data exfiltration or domain compromise. Social engineering is a core component because it validates whether employee awareness and security policies can resist real-world manipulation.

Why this answer

A red team exercise is a full-scope adversary simulation that can include social engineering and black box testing.

10
MCQeasy

Which penetration testing standard provides a structured methodology for conducting penetration tests, including pre-engagement, reconnaissance, and reporting phases?

A.NIST SP 800-115
B.OWASP Testing Guide
C.PTES
D.OSSTMM
AnswerC

PTES, the Penetration Testing Execution Standard, offers a comprehensive, structured methodology that explicitly defines seven phases: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. It standardizes both technical execution and communication, including rules of engagement, data handling, and report templates. This makes it a complete, industry-recognized standard for penetration testing, clearly surpassing the narrower guides.

Why this answer

The Penetration Testing Execution Standard (PTES) covers the entire testing lifecycle.

11
MCQhard

A penetration tester is performing a wireless penetration test. The RoE states that testing is only allowed between 8 PM and 6 AM. At 7:30 PM, the tester begins active scanning. At 8:15 PM, a client employee calls emergency contact to report suspicious activity. According to the RoE, which of the following is the most likely reason for the call?

A.The tester used an unauthorized tool
B.The tester started testing outside the agreed time window
C.The tester targeted an out-of-scope access point
D.The tester exceeded the allowed signal strength
AnswerB

Active scanning began at 7:30 PM, thirty minutes before the 8 PM window opened, so the tester breached the RoE's permitted testing hours. The employee's 8:15 PM call follows that unauthorised activity, making the early start the most likely trigger. The constraint satisfied is the agreed time window itself.

Why this answer

The RoE explicitly restricts testing to 8 PM – 6 AM, but the tester began active scanning at 7:30 PM — 30 minutes before the allowed window. Active scanning generates detectable wireless traffic (probe requests, deauth frames, association attempts) that a client employee could notice and report. The call at 8:15 PM is most likely a delayed report of the activity that started at 7:30 PM, outside the agreed window.

Exam trap

PT0-003 often tests whether candidates correctly attribute an incident to the specific RoE clause violated (timing, scope, tooling) rather than assuming the most dramatic cause like out-of-scope targeting.

How to eliminate wrong answers

Option A is wrong because the scenario provides no information about unauthorized tools; the RoE violation described is temporal, not tool-related. Option C is wrong because there is no indication the tester targeted an out-of-scope access point — the scenario only mentions timing. Option D is wrong because signal strength limits are not mentioned in the RoE excerpt provided, and the question focuses on the time-window violation.

12
MCQmedium

During an external penetration test, the tester discovers that a critical web application is hosted on a third-party cloud provider. The SOW did not mention this provider. What should the tester do before proceeding with testing against that provider's infrastructure?

A.Obtain written authorization from the third-party provider
B.Scan only the IP addresses that resolve to the client's domain
C.Continue testing as long as the target is in scope
D.Ignore the web application and test only on-premises assets
AnswerA

Obtaining written authorization from the third-party provider is mandatory because the provider owns or controls the asset; without their explicit consent, testing constitutes unauthorized access, potentially violating computer fraud laws and civil agreements. This authorization must be documented in the rules of engagement and ideally obtained before any testing begins, as the client's scope alone cannot transfer ownership rights.

Why this answer

Testing third-party services requires explicit permission from the provider to avoid legal and contractual issues.

13
MCQmedium

Which of the following is typically included in the final deliverables of a penetration test?

A.A list of all employee passwords
B.Network diagrams of the client's internal network
C.A copy of all data extracted during the test
D.Executive summary, technical findings, and remediation guidance
AnswerD

The standard components of a professional penetration testing report are an executive summary, detailed technical findings, and actionable remediation guidance. The executive summary translates business risk into non-technical terms, while the technical findings section lists vulnerabilities with evidence and exploitation details, and the remediation guidance provides prioritized, specific corrective actions. Together, these sections enable both management and technical staff to understand the security posture and implement effective fixes.

Why this answer

Standard deliverables include an executive summary, technical findings, and remediation guidance.

14
Multi-Selectmedium

A penetration tester is scoping a network penetration test for a client that uses multiple third-party services. Which TWO of the following are correct actions regarding third-party services? (Select TWO.)

Select 2 answers
A.Include all third-party services in scope without restriction
B.Assume that third-party services are out of scope
C.Test third-party services without informing the provider
D.Exclude third-party services from testing unless explicitly authorized
E.Obtain written permission from each third-party provider before testing
AnswersD, E

The correct default with third-party infrastructure is to exclude it from testing unless the provider has explicitly authorized it, because a penetration test's authorization is specific to the systems controlled and operated by the client. This conservative boundary prevents an otherwise legal engagement from crossing into systems owned by another party, thereby avoiding unauthorized access charges and preserving the tester's legal standing. If a critical third-party component must be assessed, a scoping change with written permission should be executed before any packets are sent.

Why this answer

Option D is correct because third-party services are owned and operated by external providers, so they must be excluded from the engagement scope unless the client has explicitly authorized testing of them, typically through contractual agreements or written consent. Option E is correct because testing a third-party provider's infrastructure without that provider's written permission is unauthorized access, so the tester must obtain explicit written authorization from each provider before any testing occurs. Option A is wrong because including all third-party services without restriction would authorize testing of systems the client does not own or control, creating legal and contractual violations.

Option B is wrong because assuming third-party services are automatically out of scope is not a valid scoping decision; they may be in scope if proper authorization exists. Option C is wrong because testing a third-party service without informing the provider is unauthorized and unethical, regardless of the client's request.

Exam trap

The trap here is that candidates may assume third-party services are automatically in scope because they are part of the client's infrastructure, but the exam tests the legal and contractual necessity of obtaining explicit written permission before testing any external system.

15
MCQhard

During a penetration test, the tester discovers evidence of an ongoing criminal activity, such as unauthorized data exfiltration by an insider. The client's legal team has not provided specific guidance on handling such discoveries. According to best practices and legal considerations, what should the tester do first?

A.Continue testing to gather more evidence
B.Contact law enforcement directly
C.Ignore the finding as it is out of scope
D.Stop testing and report the finding to the client immediately
AnswerD

Evidence of ongoing criminal activity triggers a legal and ethical duty that overrides the engagement scope. Halting testing preserves evidence integrity and prevents further harm, while immediate notification lets the client's legal team direct next steps, satisfying the requirement to act without specific prior guidance.

Why this answer

The correct option is D: stop testing and report the finding to the client immediately. In penetration testing, when evidence of ongoing criminal activity such as unauthorized data exfiltration by an insider is discovered and the client's legal team has not provided specific guidance, the tester's first duty is to halt testing and notify the client so their legal counsel can decide how to proceed, preserving evidence and avoiding interference with a potential investigation. Continuing testing (A) risks destroying evidence or tipping off the insider, and contacting law enforcement directly (B) bypasses the client's authority and could violate the engagement contract or legal privilege.

Ignoring the finding (C) is unethical and potentially illegal, as it conceals known criminal activity rather than escalating it through the proper client channel.

16
Multi-Selecthard

During post-engagement, a penetration tester needs to ensure proper data handling. Which THREE actions should the tester take?

Select 3 answers
A.Securely destroy test artifacts after the client accepts the report
B.Purge any data stored on test systems used during the engagement
C.Retain all test data indefinitely for future reference
D.Follow the agreed-upon data handling procedures in the contract
E.Share findings with other clients to demonstrate expertise
AnswersA, B, D

Securely destroying test artifacts after client acceptance is the final step in the data lifecycle, requiring methods such as cryptographic erase or physical shredding to render data unrecoverable. This includes scan reports, payloads, captured credentials, and network captures stored on assessment laptops or servers. Retention beyond acceptance is unnecessary unless the contract explicitly permits it, making immediate destruction a standard practice to minimize exposure.

Why this answer

After the engagement, test artifacts should be securely destroyed, data should be purged from test systems, and confidential information must be handled per agreement.

17
MCQhard

A penetration tester discovers evidence of ongoing criminal activity, such as a data breach by an internal employee, during a white box penetration test. The client's legal team has not provided specific instructions on handling such discoveries. According to best practices and legal considerations, what should the tester do first?

A.Notify law enforcement directly
B.Continue testing and document the evidence for later reporting
C.Stop testing and contact the client's emergency contact
D.Ignore the activity and proceed as planned
AnswerC

Halting all testing and invoking the client's pre-arranged emergency contact path is the only action that both preserves the integrity of forensic evidence and keeps the engagement within its legal scope. The emergency contact is typically the client's incident-response lead or executive with authority to decide whether to involve law enforcement, issue containment orders, or terminate the test. This step ensures that the tester remains a controlled, auditable resource rather than acting unilaterally on potentially sensitive criminal matters.

Why this answer

The tester should immediately stop testing and inform the client's emergency contact to handle the criminal activity appropriately.

18
MCQeasy

A penetration tester is hired to assess the security of a company's internal network. The tester is given full network diagrams, credentials, and source code. Which type of penetration test is being performed?

A.White box
B.Black box
C.Grey box
D.Red team
AnswerA

White box testing grants the tester complete knowledge of the target environment, including source code, architecture diagrams, credentials, and internal documentation. This enables deep static analysis and code-path-specific vulnerability discovery, such as identifying logic flaws or hardcoded secrets that would be invisible to a black-box approach. The elevated access reduces reconnaissance effort and speeds up the assessment, but requires the tester to prioritize findings against a vast attack surface and validate beyond mere code scanning.

Why this answer

White box testing provides the tester with full knowledge of the target environment, including credentials and documentation.

19
MCQmedium

A penetration testing company is contracted to perform a social engineering engagement. The client requests that only employees in the finance department be targeted. Which scoping consideration is most relevant?

A.Personnel scope
B.Rules of engagement
C.Production vs. staging environments
D.Third-party services
AnswerA

Personnel scope defines the specific subset of employees, departments, or roles that a social engineering campaign may legitimately target. For example, it may list all non-executive staff as in-scope but exclude executive leadership or a particular division for internal political reasons. This is the correct scoping element because the question asks where the target population is recorded, and that is precisely what the personnel scope does.

Why this answer

Personnel scope defines which individuals or groups are in-scope for social engineering testing.

20
MCQmedium

During a pre-engagement meeting, the client states that no testing is allowed on the wireless network or on any cloud-based services hosted by third parties. Which part of the engagement documentation would specify these restrictions?

A.Get-out-of-jail letter
B.Rules of engagement (RoE)
C.Statement of work (SOW)
D.Non-disclosure agreement (NDA)
AnswerB

The rules of engagement (RoE) is the official document that codifies all permissible actions, boundaries, and constraints for a penetration test, including explicit 'no testing' restrictions on designated assets or services. It also specifies emergency procedures, legal boundaries, and points of contact, ensuring both client and tester agree on the exact operational parameters. In a pre-engagement meeting, the client's stated restrictions would be formally recorded in the RoE, making it the correct document that defines what is off-limits.

Why this answer

The rules of engagement (RoE) define the scope, including what is allowed and not allowed, such as restrictions on wireless and cloud services.

21
MCQmedium

A penetration tester is conducting a red team exercise. The goal is to simulate an advanced persistent threat (APT) and test the organization's detection and response capabilities. Which of the following engagement types best describes this scenario?

A.Wireless penetration test
B.Red team exercise
C.Network penetration test
D.Web application penetration test
AnswerB

A red team exercise is a goal-based adversarial simulation that emulates the tactics, techniques, and procedures (TTPs) of real-world threat actors, often using frameworks like MITRE ATT&CK. It operates under strict rules of engagement and typically includes stealth and evasion to test the organization's detection and response capabilities, not just technical vulnerabilities. Unlike standard penetration tests, the red team's success is measured by whether it can achieve a specified objective (e.g., accessing critical data) without being detected by the blue team.

Why this answer

A red team exercise (Option B) is the correct engagement type because it simulates an advanced persistent threat (APT) by emulating real-world adversarial tactics, techniques, and procedures (TTPs) across multiple attack vectors, with the primary objective of testing the organization's detection and response capabilities. Unlike a standard penetration test, a red team exercise is goal-oriented (e.g., gaining access to a specific system or data) and often operates under a covert or no-notice scenario, requiring the team to bypass security controls and evade detection over an extended period.

Exam trap

The trap here is that candidates often confuse a red team exercise with a standard penetration test, mistakenly thinking any simulated attack qualifies as a red team exercise, but the key differentiator is the APT-style objective of testing detection and response rather than simply finding vulnerabilities.

How to eliminate wrong answers

Option A is wrong because a wireless penetration test focuses exclusively on assessing the security of wireless networks (e.g., WPA2/3, 802.1X, rogue APs) and does not simulate an APT's multi-vector, long-duration campaign. Option C is wrong because a network penetration test is a point-in-time assessment of network infrastructure vulnerabilities (e.g., open ports, misconfigured firewalls, weak SNMP strings) and does not involve the stealthy, persistent, and goal-driven behavior of an APT. Option D is wrong because a web application penetration test targets only web application vulnerabilities (e.g., SQLi, XSS, CSRF) and lacks the breadth of attack surfaces (e.g., physical, social engineering, endpoint) required to emulate an APT.

22
Multi-Selecthard

A penetration tester is preparing for a web application penetration test. The client application is hosted on a cloud platform that serves multiple tenants. Which THREE of the following are critical legal and scoping considerations?

Select 3 answers
A.Include a clause in the SOW that the tester is not liable for any data exposure
B.Understand how the client's data privacy policies affect handling of any discovered data
C.Define the types of attacks allowed (e.g., SQL injection, XSS) in the rules of engagement
D.Ensure the cloud provider has granted permission for the test
E.Test all tenant data to ensure comprehensive coverage
AnswersB, C, D

During testing, you may encounter PII, PHI, or other sensitive data. The client's data privacy policies and applicable regulations (GDPR, HIPAA, CCPA) dictate how that data must be handled, stored, and reported. Failure to comply can turn a routine pentest into a data breach with legal consequences. Therefore, understanding these policies is a crucial part of scoping and authorization.

Why this answer

Legal considerations include authorization from the cloud provider, handling sensitive data, and defining permissible testing methods.

23
MCQeasy

Which of the following is the primary purpose of a get-out-of-jail letter?

A.To outline the deliverables
B.To establish a communication plan
C.To provide legal authorization for the tester to perform the test
D.To define the rules of engagement
AnswerC

This letter is the formal 'get out of jail free' instrument that gives the penetration tester documented, lawful permission to perform activities that would otherwise constitute unauthorized access, intrusion, or computer crime under statutes such as the Computer Fraud and Abuse Act. It is signed by an authorized representative of the client organization and typically includes the tester's identity, authorized systems, and testing window to establish legal standing. Without it, even a benign network scan could expose the tester to civil liability or criminal prosecution.

Why this answer

A get-out-of-jail letter provides authorization and protects the tester from legal liability when performing authorized tests.

24
MCQhard

A penetration tester is engaged to test a web application that uses a third-party payment gateway. The client has not obtained permission from the payment gateway provider. Which of the following is the best course of action?

A.Proceed with testing but use only passive techniques on the gateway
B.Test the gateway without informing the client to avoid delays
C.Exclude the payment gateway from scope and notify the client that permission is required
D.Include the payment gateway in scope because it is part of the application
AnswerC

The payment gateway is a third-party system (e.g., Stripe, PayPal) that the client's application integrates with but does not own or operate, so it falls outside the contractual scope of the engagement. Explicitly excluding it and notifying the client ensures the tester operates solely within authorized boundaries, preventing legal liability under computer misuse laws and preserving the admissibility of findings. This approach also aligns with standard penetration testing frameworks (e.g., OWASP Testing Guide), which require validating scope with the client and documenting third-party dependencies as out-of-scope. If testing the gateway is necessary, the client must arrange a separate authorization or request an attestation from the gateway provider.

Why this answer

Third-party services require explicit permission from the provider; testing without it could violate terms or laws. The tester should add the service as out-of-scope until permission is obtained.

25
MCQmedium

The penetration tester identifies that a web application is hosted on a server that also contains sensitive customer data unrelated to the test. The SOW clearly states that only the web application is in scope. The tester accidentally accesses the customer data. What should the tester do immediately?

A.Delete the data and continue as planned
B.Continue testing and ignore the data
C.Analyze the data to find vulnerabilities
D.Report the incident to the client and stop testing
AnswerD

Stopping the test and reporting the incident is the only action that preserves both the evidence and the tester's professional integrity while aligning with incident-response procedures and the rules of engagement. The client has an incident response plan or would expect to be notified as a point of contact, so the tester should immediately escalate the discovery, halt all further testing, and let the client decide whether to involve law enforcement or take other protective action. This approach avoids unauthorized access to out-of-scope data and keeps the engagement within the agreed scope, which is the standard expected for a PT0-003 certified professional.

Why this answer

When a penetration tester accesses data outside the scope defined in the SOW, the immediate action is to stop testing and report the incident to the client. This preserves the integrity of the engagement, allows the client to assess any regulatory or contractual implications, and prevents further unauthorized access. Continuing or deleting data would compound the scope violation.

Exam trap

PT0-003 often tests the misconception that a tester should handle an out-of-scope discovery quietly (delete, ignore, or investigate), when the exam expects immediate client notification and cessation of testing.

How to eliminate wrong answers

Option A is wrong because deleting data is itself an unauthorized modification of client data and destroys evidence the client may need for incident response or regulatory notification. Option B is wrong because continuing testing after discovering out-of-scope access ignores the scope violation and may deepen the breach. Option C is wrong because analyzing the out-of-scope data to find vulnerabilities is a further unauthorized access and use of data that the tester has no authorization to examine.

26
MCQmedium

A penetration tester is planning a red team exercise for a client. The client insists that the testing should not disrupt production systems and only target a replicated staging environment. However, the tester believes that testing the production environment is necessary for realistic adversary simulation. What is the MOST appropriate course of action?

A.Negotiate with the client to include some production systems, explaining the value, and document agreed scope
B.Proceed with testing the production environment despite the client's request to ensure realism
C.Cancel the engagement because the scope is too restrictive
D.Test the staging environment and then extrapolate results to production
AnswerA

The client's non-disruption constraint governs the engagement, so the tester cannot unilaterally target production. Requesting a scope amendment through formal negotiation preserves the client relationship and ensures any production testing is authorised and documented, satisfying the realistic-simulation goal without breaching agreed boundaries.

Why this answer

Option A is correct because the tester should negotiate and document any scope changes with the client, ensuring mutual agreement and authorization before including production systems. This respects the client's risk tolerance while addressing the tester's realism concerns through formal change control. Option B is wrong because testing production without explicit authorization is unethical and potentially illegal.

Option C is wrong because canceling is premature when the scope can be renegotiated. Option D is wrong because extrapolating staging results to production is unreliable and does not provide a valid assessment of the production environment.

27
MCQmedium

During pre-engagement, a client insists that the penetration testers sign a non-disclosure agreement (NDA). However, the client refuses to provide a 'get-out-of-jail' letter. What risk does this pose to the penetration testers?

A.Increased risk of data breach
B.Higher likelihood of false positives
C.Inability to use certain tools
D.Potential legal liability if the client or third parties perceive the testing as malicious
AnswerD

The primary purpose of the pre-engagement authorization letter is to protect the penetration tester from allegations of unauthorized access. Without it, a client or a third party monitoring network traffic—such as an ISP or law enforcement—could reasonably perceive the scanning and exploitation activity as malicious and pursue criminal or civil charges. The letter documents informed consent, defines the exact scope, and names the responsible parties, thereby converting what might look like an attack into an authorized security assessment.

Why this answer

Without a 'get-out-of-jail' letter (also known as a authorization letter or testing waiver), the penetration testers have no documented legal authorization to perform the agreed-upon attacks. If the client or a third party (e.g., an ISP, law enforcement, or a security monitoring service) detects the test traffic and interprets it as malicious, the testers could face criminal charges or civil lawsuits for unauthorized access, even if the NDA is in place. The NDA only protects confidentiality, not the legality of the actions.

Exam trap

The trap here is that candidates often confuse the NDA (which protects confidentiality) with the get-out-of-jail letter (which provides legal authorization), mistakenly thinking the NDA alone is sufficient to cover liability, when in fact the NDA does not grant permission to perform intrusive testing.

How to eliminate wrong answers

Option A is wrong because the risk of a data breach is not directly increased by the absence of a get-out-of-jail letter; a data breach risk is more related to the scope of testing or data handling practices, not the legal authorization document. Option B is wrong because false positives are a technical issue related to tool configuration, signature tuning, or environmental noise, not a legal or authorization document. Option C is wrong because the inability to use certain tools is typically caused by client restrictions, network controls, or tool licensing, not by the lack of a get-out-of-jail letter; the letter does not affect tool functionality.

28
Multi-Selecteasy

Which TWO of the following are typical deliverables of a penetration test?

Select 2 answers
A.Technical findings and remediation guidance
B.User credentials for all accounts
C.Source code of the tested application
D.Video recording of the testing process
E.Executive summary
AnswersA, E

This is the core of a penetration test report, providing detailed descriptions of discovered vulnerabilities, including affected systems, exploitation steps, and impact. It must also include actionable remediation steps, such as patching, configuration changes, or code fixes, so the client can address risks. Without this, the report would not meet the engagement's objective of enabling the client to reduce risk.

Why this answer

Standard deliverables include an executive summary for management and technical findings for remediation.

29
Multi-Selecteasy

Which TWO of the following are types of penetration testing based on the level of knowledge provided to the tester? (Select TWO.)

Select 2 answers
A.Social engineering
B.Network penetration test
C.Red team
D.Black box
E.White box
AnswersD, E

Black box is a type of penetration testing where the tester has no prior knowledge of the target's internal structure, architecture, or credentials. This approach simulates an external, unprivileged attacker and forces testers to rely entirely on reconnaissance and vulnerability discovery from the outside. It is one of the three knowledge-based categories, alongside white box and gray box.

Why this answer

Black box and white box are two common types based on knowledge level; grey box is the third.

30
MCQeasy

Which type of penetration test provides the tester with full knowledge of the target environment, including network diagrams, source code, and administrative credentials?

A.Grey box
B.White box
C.Black box
D.Red team
AnswerB

White box testing grants the assessor complete visibility — network diagrams, source code and administrative credentials — so effort focuses on finding flaws rather than reconnaissance. This contrasts with black box, where no internal knowledge is supplied, and grey box, which provides partial detail.

Why this answer

A white box penetration test gives the tester full knowledge of the target, including network diagrams, source code, and administrative credentials. This full-disclosure approach lets the tester focus on finding vulnerabilities efficiently rather than spending time on reconnaissance.

Exam trap

PT0-003 often tests the distinction between knowledge levels (black/grey/white box) and engagement types (red team, purple team), so candidates who equate 'red team' with 'full knowledge' pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because a grey box test provides partial knowledge — typically some documentation or limited credentials — but not full source code and admin access. Option C is wrong because a black box test provides zero prior knowledge, simulating an external attacker who must perform reconnaissance from scratch. Option D is wrong because red team is a goal-oriented adversarial simulation (often testing detection and response), not a knowledge-disclosure category; a red team engagement can be black, grey, or white box.

31
MCQeasy

Which penetration testing standard provides a step-by-step methodology from pre-engagement through post-engagement activities, including intelligence gathering, vulnerability analysis, and exploitation?

A.PTES
B.OSSTMM
C.OWASP Testing Guide
D.NIST SP 800-115
AnswerA

The Penetration Testing Execution Standard (PTES) is explicitly designed as a step-by-step methodology for conducting penetration tests. It defines seven distinct phases—pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting—each with detailed technical guidance and deliverables. This lifecycle coverage makes PTES the most complete answer for a standard that walks an assessor through the entire engagement from scoping to final report.

Why this answer

PTES (Penetration Testing Execution Standard) covers the entire lifecycle of a penetration test.

32
MCQmedium

Which legal framework in the United States prohibits unauthorized access to computer systems and is commonly referenced in penetration testing authorization documents?

A.HIPAA
B.GLBA
C.CFAA
D.SOX
AnswerC

The Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. §1030, is the primary U.S. federal statute prohibiting unauthorized access to computers and protected systems. It criminalizes intentionally accessing a computer without authorization, or exceeding authorized access, to obtain information, cause damage, or commit fraud. This makes CFAA the legal framework that directly targets unauthorized computer access, which is why it is the correct answer.

Why this answer

The Computer Fraud and Abuse Act (CFAA) is the primary U.S. law against unauthorized computer access.

33
MCQhard

A penetration tester is contracted to perform a grey box test of a company's internal network. The client provides a VPN account for remote access but does not disclose that the account has been used by a former employee. The tester connects and is immediately locked out. Which pre-engagement document should have addressed this scenario?

A.Emergency contact list
B.Data handling agreement
C.Statement of Work (SOW)
D.Rules of Engagement (RoE)
AnswerD

The Rules of Engagement (RoE) is the authoritative document that defines the boundaries, testing windows, legal authorizations, and permissible techniques for a penetration test. In a grey box engagement, the RoE should explicitly list the provided credentials—such as usernames, passwords, API tokens, or SSO accounts—along with their validity period, or state where they will be securely delivered (e.g., an encrypted annex). This ensures the tester only uses authorized accounts and does not exceed the granted access level. Without this, the tester would have no legal proof that using those credentials was permitted.

Why this answer

The rules of engagement (RoE) should specify the accounts and credentials provided, including any limitations or known issues.

34
MCQmedium

A penetration testing engagement requires testing a production environment during business hours. The client is concerned about potential service disruption. Which document should specify the conditions under which the test must be halted?

A.Get-out-of-jail letter
B.Rules of Engagement
C.Communication plan
D.Statement of Work
AnswerB

The Rules of Engagement defines scope, timing, permitted techniques and stop conditions, so it is the document authorising the tester to halt activity if disruption risk appears. It directly satisfies the client's requirement for agreed business-hours testing safeguards.

Why this answer

The Rules of Engagement (RoE) is the definitive document that outlines the scope, authorization, and constraints of a penetration test, including explicit conditions under which testing must be halted to prevent service disruption. Unlike other documents, the RoE is a legally binding agreement that specifies technical boundaries such as IP ranges, testing windows, and stop conditions (e.g., CPU threshold exceeded or application error rate spike). This ensures the client's production environment is protected during business hours.

Exam trap

In CompTIA Pentest+, candidates often confuse the Statement of Work (SOW) with the Rules of Engagement (RoE). The SOW defines what will be done, while the RoE specifies how and under what constraints it will be done, including explicit halt conditions to prevent service disruption.

How to eliminate wrong answers

Option A is wrong because a get-out-of-jail letter (or authorization letter) is a document that provides the tester with emergency contact information and legal authorization to bypass security controls, but it does not define the technical conditions for halting the test. Option C is wrong because a communication plan outlines how and when to report findings and escalate issues, but it does not specify the technical stop conditions for the test itself. Option D is wrong because a Statement of Work (SOW) defines the high-level objectives, deliverables, and timeline of the engagement, but it lacks the granular technical constraints and halt conditions that are detailed in the Rules of Engagement.

35
MCQmedium

During a penetration test, the tester discovers evidence of an ongoing data breach that appears to involve criminal activity unrelated to the test scope. What is the tester's primary responsibility regarding this discovery?

A.Continue the test as planned and include the findings in the final report
B.Notify the client's emergency contact and follow the agreed-upon incident response procedures
C.Document the evidence and destroy it after the engagement to protect the client
D.Immediately stop testing and notify law enforcement without client approval
AnswerB

This is the correct action because a penetration test is executed under a contractual RoE that defines an explicit escalation path for exceptional findings. The tester must activate the client's named emergency contact and follow the incident response procedures to preserve evidence, contain the situation, and coordinate any law enforcement referral through the client's legal counsel. This approach balances the tester's legal duty to report criminal activity with the client's ownership of the systems and their authority to control external communications, ensuring the response is both lawful and consistent with the engagement's scope.

Why this answer

The tester should follow the incident response plan and notify the client immediately, as handling criminal activity is a legal and ethical obligation.

36
Multi-Selecthard

A penetration tester is conducting a wireless network assessment for a client. The client has provided a list of authorized SSIDs and MAC addresses of access points. During the assessment, the tester discovers a rogue access point that is not on the authorized list and is broadcasting a similar SSID to the corporate network. Which TWO of the following actions should the tester take? (Choose two.)

Select 2 answers
A.Notify the client's point of contact immediately about the rogue access point
B.Immediately deauthenticate all clients connected to the rogue access point
C.Document the rogue access point's details, including MAC address, channel, and signal strength
D.Attempt to connect to the rogue access point to determine its security configuration
E.Perform a denial-of-service attack to disable the rogue access point
AnswersA, C

Notifying the client's point of contact immediately is critical because a rogue access point could indicate a security breach or unauthorized network. The client needs to know so they can investigate and take action. This communication should follow the agreed incident response procedure. It ensures the client is aware and can mitigate any potential risks. The tester should not attempt to remediate without authorization.

Why this answer

When a rogue access point is discovered, the tester should document its details and notify the client's point of contact immediately. These actions provide the client with the necessary information to investigate and remove the rogue device, while adhering to the rules of engagement. Active countermeasures like deauthentication or DoS attacks should not be taken unless explicitly authorized.

Connecting to the rogue AP could be risky and is generally not recommended.

Exam trap

The trap here is taking active countermeasures like deauthenticating clients or launching a DoS attack, which are usually out of scope and could cause disruption.

37
MCQeasy

A penetration tester is hired to perform an assessment where the tester is provided with network diagrams, source code, and administrative credentials. Which type of penetration test is this?

A.Grey box
B.Black box
C.White box
D.Red team
AnswerC

White box testing is the correct classification because the scenario describes a penetration tester who is given full knowledge of the system, including source code, network architecture, and authorized credentials. This testing level, also known as crystal box or clear box, allows comprehensive vulnerability identification, including deep logic flaws and configuration issues, and is often used for compliance-driven reviews or post-breach security assessments. The provision of full knowledge enables the tester to focus on exploitation and reporting without spending time on reconnaissance, directly matching the prompt's conditions.

Why this answer

In a white box test, the tester has full knowledge of the environment, including credentials and documentation.

38
MCQeasy

During the pre-engagement phase, which document defines the IP ranges, test windows, and emergency stop criteria for a penetration test?

A.Get-out-of-jail letter
B.Non-Disclosure Agreement (NDA)
C.Statement of Work (SOW)
D.Rules of Engagement (RoE)
AnswerD

The Rules of Engagement (RoE) is the authoritative document that translates the client's authorization into actionable, technical constraints. It explicitly defines allowed target IP ranges, domains, and systems; test execution windows; permitted tools and attack techniques; escalation paths; and unambiguous stop criteria—such as 'halt testing immediately if any production system fails.' RoE is typically signed by both parties and serves as the singular reference for allowable activities, ensuring no tester exceeds scope and no client is caught off guard.

Why this answer

The Rules of Engagement (RoE) document specifies technical constraints like IP ranges, timing, and stop conditions.

39
MCQmedium

A penetration tester is planning a web application test. The client wants to minimize risk to production data. Which environment should the tester recommend for testing?

A.Development environment with live data
B.Production environment with a read-only database
C.Staging environment with anonymized data
D.Production environment with full access
AnswerC

Staging with anonymized data is the preferred testing ground because it replicates the production topology, configurations, and code version while eliminating the risk of exposing genuine personal data. Anonymization techniques such as tokenization or data masking preserve the relational integrity and data format needed for accurate vulnerability discovery. This environment allows comprehensive testing without the high-stakes consequences of touching live workloads.

Why this answer

Testing in a staging environment reduces the risk of impacting live data and systems.

40
MCQeasy

A penetration tester is preparing a deliverable for a client. Which of the following should be included in the final report?

A.Executive summary, technical findings, and remediation guidance
B.The tester's personal notes and observations
C.Only the technical findings
D.Only the executive summary
AnswerA

The standard penetration test deliverable comprises an executive summary for non-technical stakeholders, detailed technical findings for security engineers, and remediation guidance to address identified vulnerabilities. This structure ensures every audience—from management to IT—receives actionable information tailored to their role. It aligns with industry best practices such as the PTES report format and enables the client to prioritize and fix issues effectively.

Why this answer

A standard penetration testing report includes an executive summary, technical findings, and remediation guidance.

41
Multi-Selectmedium

A penetration testing firm is scoping a network penetration test for a client. The client has provided a list of IP ranges and subnets. Which TWO of the following should the tester consider when defining the scope?

Select 2 answers
A.Identify any third-party hosted services within the provided IP ranges and obtain explicit permission
B.Define which IP ranges are out of scope and document them
C.All IP addresses owned by the client are in scope
D.Test all IP addresses regardless of ownership to ensure complete coverage
E.Include all subnets that are routable from the internet
AnswersA, B

When an IP range is provided for a network penetration test, it may contain addresses owned by the client but operated by third parties, such as cloud providers, CDNs, or SaaS vendors. Testing those systems requires separate written authorization from the actual owner, because the client's permission does not extend to third-party infrastructure. You must therefore proactively identify any third-party hosted services within the provided ranges and obtain explicit permission before active testing to stay within legal and ethical boundaries.

Why this answer

Scoping must distinguish in-scope vs out-of-scope assets and address third-party services that require permission.

42
Multi-Selecteasy

Which THREE of the following are common components of a pre-engagement agreement between a penetration tester and a client?

Select 3 answers
A.List of all employee passwords
B.Rules of Engagement (RoE)
C.Statement of Work (SOW)
D.Non-Disclosure Agreement (NDA)
E.Full source code of the target application
AnswersB, C, D

RoE is a critical pre-engagement document that defines the authorized testing boundaries, including allowed techniques, testing windows, IP ranges, emergency contacts, and prohibited actions. It establishes the legal and operational limits for the penetration test, such as whether social engineering or denial-of-service attacks are permitted. This ensures both client and tester agree on acceptable behavior, preventing scope creep and misunderstandings.

Why this answer

Pre-engagement typically includes SOW, RoE, NDA, permission letters, emergency contacts, and communication plans.

43
MCQeasy

Which penetration testing standard provides a methodology that includes pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting?

A.OSSTMM
B.NIST SP 800-115
C.OWASP Testing Guide
D.PTES
AnswerD

PTES is the correct answer because it defines a complete penetration testing methodology with seven distinct phases, including pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This structure explicitly incorporates both technical execution and business/legal considerations, providing a comprehensive standard that fully covers the penetration testing lifecycle from initial scoping to final client deliverable.

Why this answer

The Penetration Testing Execution Standard (PTES) is the only standard among the options that explicitly defines a full penetration testing methodology with the phases listed: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. PTES provides a structured, seven-phase framework designed specifically for penetration testers, making it the correct choice for this question.

Exam trap

The trap here is that candidates often confuse the OWASP Testing Guide (Option C) as a general penetration testing standard because it is widely known, but it is strictly limited to web application security and does not cover the full lifecycle of a penetration test as defined in the question.

How to eliminate wrong answers

Option A is wrong because the Open Source Security Testing Methodology Manual (OSSTMM) focuses on operational security metrics and channel-based testing (e.g., human, physical, wireless, telecommunications, and data networks) rather than a sequential penetration testing methodology with the specific phases listed. Option B is wrong because NIST SP 800-115 is a technical guide for information security testing and assessment, but it does not prescribe a formal penetration testing methodology with phases like pre-engagement interactions or post-exploitation; it is more of a general assessment framework. Option C is wrong because the OWASP Testing Guide is specifically focused on web application security testing and does not cover the full scope of a penetration test, including pre-engagement interactions, threat modeling in the context of network or system testing, or post-exploitation activities beyond web applications.

44
MCQeasy

A penetration tester is hired to assess the security of a company's internal network. The client provides the tester with full network diagrams, credentials, and source code. Which type of penetration test is being performed?

A.Grey box
B.Black box
C.Red team
D.White box
AnswerD

White box testing, also called clear box or open box testing, gives the tester full knowledge of the target environment, including source code, architecture diagrams, configuration files, and administrative credentials. This comprehensive visibility allows the pentester to perform detailed code review, identify programming flaws, and validate configuration hardening with maximum efficiency. When the engagement premise states the tester is provided complete system details, white box is the only correct classification.

Why this answer

White box testing provides the tester with full knowledge and credentials, which matches the scenario.

45
MCQmedium

A penetration tester is about to start an engagement. Which document outlines the IP ranges that are in scope, the testing window, and the emergency stop criteria?

A.Non-Disclosure Agreement (NDA)
B.Statement of Work (SOW)
C.Rules of Engagement (RoE)
D.Get-out-of-jail letter
AnswerC

The RoE is the authoritative operational document that directly defines the technical constraints and legal boundaries of the penetration test. It includes the exact authorized IP ranges/networks, permitted testing times (including any blackout windows), allowed test types (e.g., active exploitation, social engineering), handling of sensitive data, and specific stop conditions or escalation paths if critical systems fail. Unlike the NDA or SOW, the RoE is the document testers must consult minute-to-minute to ensure every action is authorized and safe.

Why this answer

The rules of engagement (RoE) specify technical and procedural boundaries for the test.

46
MCQmedium

After completing a penetration test, the tester must deliver a report. According to standard practices, which of the following is a required component of the deliverables?

A.Executive summary, technical findings, and remediation guidance
B.Remediation guidance and a list of all tested IPs
C.Only technical findings and proof-of-concept code
D.Executive summary and raw data logs
AnswerA

A penetration test report must communicate risk to both business and technical audiences. The executive summary conveys impact to leadership, technical findings document exploited vulnerabilities with evidence, and remediation guidance tells the client how to fix them, satisfying the deliverable's dual-audience requirement.

Why this answer

A typical penetration test report includes an executive summary, technical findings, and remediation guidance.

47
MCQeasy

A penetration tester is preparing for a social engineering engagement. The client has requested that the tester attempt to gain access to the building by impersonating a delivery person. Which of the following should the tester obtain from the client before conducting the test?

A.A copy of the client's security policy
B.A non-disclosure agreement (NDA)
C.A list of employee names and phone numbers
D.A get-out-of-jail letter
AnswerD

The get-out-of-jail letter is essential for physical social engineering engagements. It authorizes the tester to be on the premises and protects them from legal action if they are caught impersonating a delivery person. It should be signed by an authorized client representative and kept on the tester's person during the engagement. This document is critical for legal protection and proof of authorization.

Why this answer

For physical social engineering engagements, the tester must obtain a get-out-of-jail letter from the client. This document authorizes the tester to be on the premises and protects them from legal action if they are caught. It is essential for legal protection and should be carried at all times during the engagement.

Other documents like NDAs or security policies do not provide this authorization.

Exam trap

The trap here is thinking that an NDA or security policy is sufficient, but only the get-out-of-jail letter authorizes physical entry and protects against trespassing charges.

48
MCQmedium

A penetration tester is preparing a proposal for a client. The client wants a test that includes a detailed technical report with remediation steps and an executive summary for management. Which standard or framework is most commonly used to structure the testing process from pre-engagement through post-engagement?

A.OWASP Testing Guide
B.OSSTMM
C.PTES
D.NIST SP 800-115
AnswerC

PTES (Penetration Testing Execution Standard) is the correct choice because it defines a comprehensive, industry-recognized framework covering all seven phases of a penetration test: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This structure is specifically designed for professional penetration testing engagements, ensuring that legal boundaries are established, scoping is thorough, and deliverables are actionable and client-focused. Its widespread adoption and practical focus make it the most suitable methodology to cite in a proposal promising a full, end-to-end penetration test.

Why this answer

The Penetration Testing Execution Standard (PTES) provides a comprehensive framework covering all phases from pre-engagement to post-engagement.

49
Multi-Selecteasy

A company is planning a social engineering engagement. Which TWO items should be included in the pre-engagement documentation?

Select 2 answers
A.List of all employee passwords
B.Network topology diagrams
C.Source code of all applications
D.Emergency contact list
E.Rules of engagement
AnswersD, E

An emergency contact list is a mandatory deliverable for social engineering engagements because any deployed scenario could accidentally trigger a real security incident or expose a worker to harm. The lead tester needs named individuals with the authority to approve an immediate abort, making this list as operationally important as the RoE itself. Without these contacts, a seemingly harmless test could spiral out of control with no rapid way to stop it.

Why this answer

Pre-engagement documentation should include the rules of engagement (RoE) and emergency contacts to handle incidents during social engineering.

50
Multi-Selecthard

A penetration testing company is planning a social engineering engagement for a client. The engagement includes phishing and physical tailgating. Which THREE of the following should be clearly defined in the Rules of Engagement? (Select THREE.)

Select 3 answers
A.The format of the final report
B.The specific vulnerabilities to be exploited
C.The conditions under which the test must be stopped immediately
D.The types of social engineering attacks allowed (e.g., phishing, vishing, tailgating)
E.The list of employees and contractors who are in scope for social engineering
AnswersC, D, E

Emergency stop criteria, often called 'cease-and-desist' or 'safety stop' conditions, are an indispensable RoE section that enumerates triggering events such as evidence of life-threatening incidents, unexpected system catastrophic failures, or unauthorized access to protected health/financial data. This clause clarifies that the tester's authority to act is revocable in real time and defines the chain of communication for immediate shutdown. Absent this, the client retains no operational control over a live, rolling attack scenario, which is both a legal and safety hazard.

Why this answer

RoE should address personnel scope, emergency stop conditions, and specific techniques allowed; vulnerabilities and deliverables are part of SOW.

51
MCQmedium

A client requests a penetration test that includes testing of both internal network devices and a public-facing web application. The tester is provided with a VPN account for internal access but no credentials for the web application. Which type of penetration test is this?

A.White box
B.Red team
C.Grey box
D.Black box
AnswerC

Grey box testing grants the tester partial knowledge of the target, such as standard user credentials, VPN access, or basic network visibility, without exposing full architecture or privileged credentials. This directly matches the client's request, where VPN access gives a realistic internal foothold while still requiring the tester to discover vulnerabilities, escalate privileges, and move laterally, making grey box the correct answer.

Why this answer

Grey box testing involves partial knowledge; the tester has internal network access but not web app credentials.

52
Multi-Selectmedium

In a red team exercise, the team wants to simulate a realistic adversary. Which TWO of the following are typically included in the scope of a red team engagement compared to a standard penetration test?

Select 2 answers
A.Extensive vulnerability scanning of all in-scope systems
B.Comprehensive compliance verification against standards
C.Physical security testing (e.g., tailgating, lock picking)
D.Detailed reporting of all vulnerabilities found
E.Social engineering attacks against employees
AnswersC, E

Physical security testing is a legitimate and often essential component of a red team engagement because real-world adversaries frequently exploit physical access as an initial foothold or alternate path into network resources. Techniques like tailgating into a secured office, picking locks to access server rooms, or cloning employee badges allow the red team to simulate a full-scope attacker who does not simply rely on remote network access. By physically penetrating a facility, the team can demonstrate how seemingly separate physical and logical security controls can be chained into a critical business impact.

Why this answer

Red team exercises often include physical and social engineering attacks, and may attempt to remain undetected for longer periods.

53
Multi-Selecthard

A penetration tester discovers evidence of an ongoing criminal activity (e.g., data exfiltration by an insider) during a test. According to best practices and legal considerations, which THREE actions should the tester take?

Select 3 answers
A.Preserve all evidence and document findings for law enforcement
B.Publicly disclose the finding on a vulnerability disclosure platform
C.Immediately stop all testing activities
D.Contact the client's emergency contact per the communication plan
E.Continue testing to gather more evidence
AnswersA, C, D

Preserving evidence is a forensic priority; you must create a chain of custody by recording exactly what was observed, when, and from which system, and avoid altering or deleting any data. Use write-blockers or forensic imaging if feasible, and document all findings with timestamps and system details so law enforcement can use the evidence in a legal proceeding. This action is correct because it directly supports the investigation without overstepping your engagement scope.

Why this answer

When discovering criminal activity, the tester should stop testing, notify the client contact, and preserve evidence for investigation.

54
MCQhard

A penetration tester is scoping a test for a client that uses a SaaS application for customer relationship management. The client wants the tester to assess the application's security. What is the most important consideration regarding this SaaS application?

A.The application is hosted on the cloud, so it is automatically in scope
B.The tester should obtain explicit permission from the SaaS provider before testing
C.The tester should only test the client's configuration of the SaaS application
D.The tester can test the application as long as the client provides administrative credentials
AnswerB

When a client uses a third-party SaaS application, the client is only a subscriber and does not own the application's infrastructure or code. The provider retains control over the platform, so any active security testing that targets the application must be explicitly authorized by the provider. This authorization typically takes the form of a written agreement, a penetration-testing rider in the service contract, or a documented engagement with the provider. Without the provider's explicit permission, the tester would be performing unauthorized access against a system they do not own, which could be illegal and could impact other tenants.

Why this answer

The tester must ensure that the SaaS provider's terms of service allow security testing and that permission is obtained.

55
MCQhard

A penetration tester is conducting a red team engagement for a financial institution. The client has requested that the tester simulate a ransomware attack to test the incident response process. During the test, the tester encrypts a file share containing simulated customer data. The client's security team detects the encryption and initiates their incident response plan. Which of the following should the tester do FIRST to ensure the engagement remains within scope and does not cause operational disruption?

A.Document the encryption activity and wait for the client's incident response team to contact the tester
B.Attempt to exfiltrate the simulated customer data to test data loss prevention controls
C.Immediately stop all testing activities and notify the primary point of contact
D.Continue encrypting additional file shares to fully simulate the ransomware attack
AnswerC

The tester should immediately stop testing and notify the primary point of contact. This action ensures that the client's incident response team is aware that the encryption is part of the authorized test, preventing unnecessary escalation or operational disruption. It also allows the client to verify that the test is within scope and that no real data is at risk. Continuing without notification could lead to confusion and potential legal issues.

Why this answer

In a red team engagement, when the client's incident response team detects simulated malicious activity, the tester should immediately stop testing and notify the primary point of contact. This prevents unnecessary escalation and operational disruption, and confirms that the activity is authorized. Continuing the attack or exfiltrating data could exceed the scope and cause unintended consequences.

Proactive communication is key to maintaining trust and safety.

Exam trap

The trap here is thinking that continuing the attack is necessary to fully test the incident response, but it risks operational disruption and going out of scope.

56
Multi-Selectmedium

After completing a penetration test, the tester must handle test artifacts appropriately. Which TWO of the following are best practices for data handling and destruction?

Select 2 answers
A.Securely delete all test data after the engagement is complete
B.Return any client data to the client before destruction
C.Keep all test data indefinitely for future reference
D.Store test data in an unencrypted archive on the tester's laptop
E.Share test data with other clients for benchmarking
AnswersA, B

Securely deleting all test data post-engagement is correct because penetration testing engagements typically operate under a data-handling agreement that mandates the tester to either return or destroy all client data upon conclusion. Secure deletion goes beyond normal file removal—it requires cryptographic erase, overwriting with validated patterns (e.g., NIST SP 800-88 Purge), or physical destruction to ensure data is irrecoverable. This mitigates the risk of inadvertent disclosure, maintains client confidentiality, and aligns with the principle of data minimization.

Why this answer

Best practices include securely erasing test data and returning any client data to the client.

57
MCQhard

A penetration tester is conducting a wireless penetration test. The client's rules of engagement state that testing must not disrupt production services. During the test, the tester's de-authentication attack causes the company's guest Wi-Fi to go offline. What should the tester do?

A.Ignore the issue and complete the test
B.Reduce the intensity of the attack
C.Continue testing because guest Wi-Fi is not critical
D.Stop testing and follow the emergency stop procedure
AnswerD

Stopping the test and executing the emergency stop procedure is the mandated response to an unintended service disruption. This action immediately prevents further impact, triggers the client notification and incident response plan, and allows the tester to document the incident as part of the test results. Following the procedure also preserves the integrity of the test and demonstrates compliance with the RoE, protecting both the tester and the client.

Why this answer

According to the RoE, the tester must stop testing if there is an emergency or disruption. The tester should follow the emergency stop procedure and contact the client.

58
MCQmedium

Which legal framework in the United States makes it a crime to access a computer system without authorization, and is a key consideration when obtaining permission for penetration testing?

A.SOX
B.HIPAA
C.GDPR
D.CFAA
AnswerD

The CFAA (Computer Fraud and Abuse Act), codified at 18 U.S.C. § 1030, is the primary US federal law that criminalizes unauthorized access to computers and computer networks. It prohibits hacking, exceeding authorized access to obtain information, and causing damage to protected computers, including those used in interstate or foreign commerce. The CFAA is the correct answer because it directly establishes criminal liability for unauthorized computer access.

Why this answer

The Computer Fraud and Abuse Act (CFAA) is the primary US law against unauthorized access.

59
MCQmedium

Which of the following best describes the purpose of a vulnerability disclosure policy in the context of a penetration test?

A.To list the assets that are out of scope
B.To define the rules of engagement for the test
C.To establish a process for reporting discovered vulnerabilities to the client and possibly to the public
D.To provide legal protection to the tester
AnswerC

The primary purpose of a vulnerability disclosure policy is to establish a clear, agreed-upon process for reporting discovered vulnerabilities to the client and, where necessary, to the public after an embargo period or remediation. It sets expectations for how findings are communicated, who is responsible for triage, and what conditions trigger coordinated disclosure — protecting the client from surprise and the tester from accusations of irresponsible release. This is the central function of the policy in any professional engagement.

Why this answer

A vulnerability disclosure policy outlines how vulnerabilities found during testing will be reported and remediated.

60
MCQmedium

A penetration tester is planning a test that involves scanning for vulnerabilities across a large IP range. The client has provided a list of IPs that are in-scope, but the tester notices that some IPs belong to a third-party company hosting a client application. What should the tester do?

A.Assume the client has permission and scan all IPs
B.Exclude the third-party IPs and notify the client
C.Scan the IPs because they are on the client's list
D.Scan only the third-party IPs that respond to ping
AnswerB

The correct action is to exclude the third-party IPs from active scanning and promptly notify the client that these assets are outside the authorized scope. This respects the legal boundaries of the engagement and ensures that the client takes responsibility for obtaining permission from the third-party owner if the assets need to be tested. The penetration tester should document the exclusion and request explicit written authorization or a revised scope before performing any scanning activity against those IPs. This approach aligns with contractual requirements, legal compliance, and professional standards in penetration testing.

Why this answer

The tester must ensure that all in-scope IPs are authorized. If an IP belongs to a third party, the tester needs written permission from that provider before testing.

61
MCQmedium

Which of the following penetration testing standards includes detailed guidelines for pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting?

A.OSSTMM
B.OWASP Testing Guide
C.NIST SP 800-115
D.PTES
AnswerD

PTES (Penetration Testing Execution Standard) is the only option that expressly defines a complete penetration testing methodology from start to finish. It covers pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This makes it a comprehensive standard suitable for guiding all phases of a professional penetration test.

Why this answer

PTES (Penetration Testing Execution Standard) covers the entire testing lifecycle from pre-engagement to reporting.

62
MCQeasy

A penetration tester is hired to perform a test with no prior knowledge of the target environment. The tester is given only the company name and must gather all necessary information from public sources. Which type of penetration test is this?

A.Grey box
B.Black box
C.Red team
D.White box
AnswerB

A black box penetration test supplies the tester with no internal knowledge, only the public-facing scope (e.g., a domain or IP address), requiring full reconnaissance through OSINT and active scanning. This directly matches the stated condition of 'no prior knowledge' because all network topology, application behavior, and potential vulnerabilities must be uncovered from scratch, replicating an external attacker's perspective.

Why this answer

In a black box test, the tester has no prior knowledge or credentials, simulating an external attacker.

Ready to test yourself?

Try a timed practice session using only Engagement Management questions.