GPEN Pen Test Planning Practice Question
A healthcare client hires your team for an internal penetration test. During the kickoff meeting, the client's compliance officer asks which document formally defines the specific systems, time windows, and testing techniques that are authorized for the engagement. Which document should you reference?
⚠ Common exam trap
Candidates often confuse high-level contractual documents such as the Statement of Work or master services agreement with the operational Rules of Engagement that actually govern testing boundaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Rules of Engagement
The Rules of Engagement is the document that operationalizes the engagement by listing authorized targets, permitted techniques, testing windows, escalation contacts, and data handling requirements. It bridges contractual documents like the Statement of Work and the actual execution of testing, giving compliance and legal stakeholders a clear, auditable definition of what is and is not allowed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Statement of Work
Why it's wrong here
The Statement of Work defines deliverables, pricing, timelines, and high-level objectives, but it typically does not enumerate specific in-scope hosts, allowed attack techniques, or testing windows. While it is a foundational contract, it lacks the operational granularity the compliance officer needs. The Rules of Engagement supplements the Statement of Work with those precise testing boundaries.
- ✗
The master services agreement
Why it's wrong here
A master services agreement establishes the overarching legal and business relationship between the client and the testing firm, covering liability, payment terms, and general contracting provisions. It does not specify individual engagement targets, testing windows, or permitted techniques. Those operational details are captured in the Rules of Engagement for each specific engagement.
- ✓
The Rules of Engagement
Why this is correct
The Rules of Engagement is the governing document that specifies authorized targets, testing windows, allowed techniques, emergency contacts, and handling of sensitive findings. It translates the Statement of Work into operational boundaries. For a healthcare client with compliance concerns, the Rules of Engagement provides the auditable record that testing stayed within agreed limits, satisfying both legal and regulatory expectations.
- ✗
The Non-Disclosure Agreement
Why it's wrong here
A Non-Disclosure Agreement governs confidentiality of information exchanged between parties. It does not define which systems may be tested, when testing may occur, or what techniques are permitted. While important for protecting sensitive healthcare data, it is not the document that establishes the technical and temporal scope of the penetration test itself.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.