Courseiva
Pen Test Planning →easyMultiple Choice

GPEN Pen Test Planning Practice Question

A healthcare client hires your team for an internal penetration test. During the kickoff meeting, the client's compliance officer asks which document formally defines the specific systems, time windows, and testing techniques that are authorized for the engagement. Which document should you reference?

⚠ Common exam trap

Candidates often confuse high-level contractual documents such as the Statement of Work or master services agreement with the operational Rules of Engagement that actually govern testing boundaries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Rules of Engagement

The Rules of Engagement is the document that operationalizes the engagement by listing authorized targets, permitted techniques, testing windows, escalation contacts, and data handling requirements. It bridges contractual documents like the Statement of Work and the actual execution of testing, giving compliance and legal stakeholders a clear, auditable definition of what is and is not allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Statement of Work

    Why it's wrong here

    The Statement of Work defines deliverables, pricing, timelines, and high-level objectives, but it typically does not enumerate specific in-scope hosts, allowed attack techniques, or testing windows. While it is a foundational contract, it lacks the operational granularity the compliance officer needs. The Rules of Engagement supplements the Statement of Work with those precise testing boundaries.

  • ✗

    The master services agreement

    Why it's wrong here

    A master services agreement establishes the overarching legal and business relationship between the client and the testing firm, covering liability, payment terms, and general contracting provisions. It does not specify individual engagement targets, testing windows, or permitted techniques. Those operational details are captured in the Rules of Engagement for each specific engagement.

  • ✓

    The Rules of Engagement

    Why this is correct

    The Rules of Engagement is the governing document that specifies authorized targets, testing windows, allowed techniques, emergency contacts, and handling of sensitive findings. It translates the Statement of Work into operational boundaries. For a healthcare client with compliance concerns, the Rules of Engagement provides the auditable record that testing stayed within agreed limits, satisfying both legal and regulatory expectations.

  • ✗

    The Non-Disclosure Agreement

    Why it's wrong here

    A Non-Disclosure Agreement governs confidentiality of information exchanged between parties. It does not define which systems may be tested, when testing may occur, or what techniques are permitted. While important for protecting sensitive healthcare data, it is not the document that establishes the technical and temporal scope of the penetration test itself.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.