GPEN Pen Test Planning Practice Question
A client asks you to perform a penetration test on their internal network. During the planning phase, they provide you with a list of IP addresses and ask you to sign a document that limits your testing to those addresses. Which of the following best describes the purpose of this document?
⚠ Common exam trap
Many exam-takers confuse a scope authorization document with other legal agreements like NDAs or liability waivers, which serve different purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It defines the scope of the engagement and legally authorizes testing only on the specified targets.
The document is a scope and authorization agreement. It legally permits testing only on specified IP addresses and protects both parties by clearly defining what is allowed. Without it, testing could be deemed unauthorized, leading to legal consequences.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is a liability waiver that absolves the tester of any responsibility for system damage.
Why it's wrong here
A liability waiver may be included in a contract, but it does not define scope or authorize testing. The document described is about limiting testing to certain IP addresses, which is a scope definition. A waiver alone would not protect the tester if they tested outside the agreed scope.
- ✗
It is a service level agreement outlining the expected uptime of the target systems during testing.
Why it's wrong here
A service level agreement (SLA) defines performance and availability guarantees, not testing boundaries. The document in question restricts testing to specific IPs, which is unrelated to uptime commitments. An SLA would not typically list target addresses or authorize testing activities.
- ✓
It defines the scope of the engagement and legally authorizes testing only on the specified targets.
Why this is correct
This document is a scope agreement and authorization letter. It ensures that the tester only targets the agreed-upon IP addresses, protecting both parties legally. Testing outside this scope could be considered unauthorized access, even if the client verbally approved a broader range. It is a fundamental component of the Rules of Engagement.
- ✗
It serves as a non-disclosure agreement to protect the client's confidential information.
Why it's wrong here
While an NDA is often part of a penetration testing contract, it does not define the scope of testing. The document described specifically limits testing to certain IP addresses, which is a scope limitation, not a confidentiality agreement. Confusing the two could lead to legal misunderstandings about what is authorized.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.