Courseiva

CEH Introduction to Ethical Hacking Practice Question

A junior security consultant is preparing to conduct an authorized penetration test for a retail client. Before any scanning begins, the client's legal team asks the consultant to confirm which document defines the exact IP ranges, testing window, and prohibited actions such as denial-of-service attempts. Which document should the consultant reference?

⚠ Common exam trap

The trap here is assuming any signed contract, such as an NDA or SOW, grants permission to test, when only the Rules of Engagement specifies targets and prohibited actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rules of Engagement (RoE)

Before active testing, an ethical hacker must operate under explicit written authorization that defines scope, timing, and restrictions. The Rules of Engagement captures those operational constraints, including in-scope IP ranges and forbidden actions such as denial-of-service. Referencing it ensures the consultant stays within legal and contractual boundaries and can demonstrate authorization if questioned during the engagement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Statement of Work (SOW)

    Why it's wrong here

    A Statement of Work describes deliverables, timeline, and pricing for a project, which is useful commercially but not the primary source for technical boundaries like allowed IP ranges and prohibited attack types. The SOW may reference the RoE for those details. The consultant needs the document that directly authorizes and constrains the testing activity itself.

  • ✓

    Rules of Engagement (RoE)

    Why this is correct

    The Rules of Engagement is the document that scopes an authorized test: it names in-scope targets, allowed techniques, testing windows, and explicitly forbidden actions like DoS. Because the client's legal team is asking about IP ranges and prohibited actions, the RoE is the authoritative source. It protects both parties by ensuring the tester's actions stay within written authorization.

  • ✗

    Non-Disclosure Agreement (NDA)

    Why it's wrong here

    An NDA governs confidentiality of information learned during the engagement; it does not define target IP ranges, testing hours, or which intrusive techniques are permitted. While an NDA is commonly signed alongside testing paperwork, it cannot tell the consultant what systems may be touched or when. The legal team's question about scope and prohibited actions points to a different document.

  • ✗

    Master Service Agreement (MSA)

    Why it's wrong here

    An MSA is a broad contract establishing general terms for an ongoing business relationship between vendor and client, such as payment and liability. It typically does not enumerate specific IP ranges, test windows, or banned techniques for a particular engagement. Those operational specifics belong in a per-engagement document rather than the overarching contract framework.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.