GPEN · domain
Pen Test Planning
The Pen Test Planning domain covers scoping, legal authorization, and engagement design before any exploitation begins. GPEN questions present client scenarios and ask you to select the correct document, testing methodology, or escalation path. Expect to reason about Rules of Engagement, authorization boundaries, third-party hosting, and how target knowledge shapes test design and reporting.
Focused practice
Practice Pen Test Planning questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Pen Test Planning
Given a client scenario, identify the governing document, correct testing methodology, and whether authorization covers every target. The single most important thing: never test an asset without documented, written permission from the party that owns or hosts it.
Rules of Engagement defining scope, authorized targets, time windows, and emergency contacts
Black-box, gray-box, and white-box methodologies and the target knowledge each provides
Written authorization and third-party cloud hosting consent before testing external assets
Scoping statements of work that bound IP ranges, applications, and testing limitations
Watch out for
Common Pen Test Planning exam traps
- ▸Treating a verbal go-ahead or email as sufficient authorization when written permission from the asset owner is required
- ▸Confusing gray-box (partial knowledge) with black-box (zero knowledge) when the scenario describes credentials or documentation provided
- ▸Ignoring third-party cloud provider restrictions and testing hosted assets without the provider's written consent
Question index
All Pen Test Planning questions (31)
Click any question to see the full explanation, or start a practice session above.
A client asks you to perform a penetration test on their internal network. During the planning phase, they provide you with a list of IP addresses and ask you to sign a document that limits your testing to those addresses. Which of the following best describes the purpose of this document?
Easy2During the planning phase of a penetration test for a multinational corporation, you discover that the client's legal department requires all testing activities to comply with the laws of each country where their offices are located. The client has offices in Germany, Brazil, and Japan. Which of the following is the MOST important consideration when planning the engagement?
Hard3You are drafting the Rules of Engagement (RoE) for a penetration test of a client's internal network. The client wants to ensure that the engagement is legally sound and that all parties understand their responsibilities. Which TWO of the following items are essential to include in the RoE? (Choose two.)
Medium4A software-as-a-service provider engages your team for a penetration test of its production environment. The client wants testing to occur during business hours so its engineers can observe. Which planning consideration is MOST important to address in the Rules of Engagement before testing begins?
Medium5You are the lead penetration tester for a financial services client. During the scoping meeting, the client states they want to test their external perimeter but are concerned about accidental disruption to production trading systems. They ask you to propose a testing approach that minimizes operational risk while still validating exploitable vulnerabilities. Which of the following is the MOST appropriate recommendation?
Medium6A client asks for an 'unannounced' penetration test to test their incident response team. What is the most important preparatory step before commencing this exercise?
Medium7You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to ensure that any protected health information (PHI) accessed during testing is handled securely. Which of the following is the MOST critical element to include in the data handling plan?
Hard8Refer to the exhibit. You are currently at 17:15. You have just identified a critical, easily exploitable vulnerability on 10.1.1.20. What is the correct next step?
Hard9You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to test a new patient portal hosted on AWS. During the kickoff meeting, the client's legal team asks how you will handle any protected health information (PHI) that you might encounter. Which of the following is the most appropriate action to take before testing begins?
Medium10When planning for an engagement involving sensitive data, which TWO of the following must be included in the data handling plan?
Medium11If a penetration tester discovers a vulnerability that could compromise a third-party hosted service during an engagement, what is the correct professional responsibility?
Medium12A healthcare client hires your team for an internal penetration test. During the kickoff meeting, the client's compliance officer asks which document formally defines the specific systems, time windows, and testing techniques that are authorized for the engagement. Which document should you reference?
Easy13A financial services client engages you for an external penetration test and wants contractual protection before testing begins. Which TWO items belong in a master services agreement or statement of work to limit the firm's legal exposure while authorizing the work? (Choose two.)
Hard14Refer to the exhibit. You are performing a penetration test based on this policy. You discover an unpatched SQL injection vulnerability on 192.168.10.20 that could be used to trigger a database lock-up. What is the most appropriate course of action?
Hard15You are planning a penetration test for a client with a large wireless network. The client wants to assess the security of their WPA3-Enterprise deployment. Which of the following should be included in the Rules of Engagement to address the risk of disrupting legitimate wireless users?
Medium16During the scoping phase of a penetration test for a global e-commerce client, you identify that the client uses a cloud-based Content Delivery Network (CDN) to host static assets. Which action is the most critical for ensuring the engagement remains within the Rules of Engagement (RoE)?
Medium17Which document is primarily responsible for defining the 'Rules of Engagement' (RoE) in a penetration testing project?
Easy18You are planning a penetration test for a client that has a hybrid cloud environment. The client's security team wants to ensure that the test does not violate the shared responsibility model of their cloud provider. Which of the following should you do FIRST to align the test with the cloud provider's policies?
Medium19You are the lead penetration tester for an engagement at a regional bank. The client's legal team has approved testing of their external IP range, but the Statement of Work does not mention the third-party core banking platform hosted by a vendor on a shared subnet. During reconnaissance, you discover that one of the client's external IPs routes directly into the vendor's shared environment. What is the MOST appropriate action before conducting any exploitation?
Medium20During planning, a client requests that you use a specific automated scanner that is known to produce false positives and potential system instability. What is the most professional way to handle this request?
Medium21During a penetration test for a multinational retailer, you discover that a legacy internal application in scope contains a hardcoded credential that also grants access to a payment processing system the client explicitly excluded from testing. You have not yet used the credential. What is the MOST appropriate course of action?
Hard22When defining the 'Scope' for a penetration test, which THREE factors are critical to document to ensure the engagement is legally and operationally sound?
Medium23You are drafting the Rules of Engagement for an internal penetration test. Which TWO of the following items are considered mandatory for the 'Communication Plan' section?
Medium24Which of the following best describes the 'Gray-box' testing methodology?
Medium25A client asks you to perform a penetration test on their web application. During the planning phase, they mention that the application is hosted on a third-party cloud provider and they do not have written permission from the provider to test the underlying infrastructure. What is the MOST appropriate action?
Easy26An enterprise client insists on a blind 'black-box' penetration test where the testing team receives zero prior knowledge regarding network architecture, IP ranges, or applications. However, the client's primary objective is to thoroughly test deep-seated business logic vulnerabilities within a critical custom web application. Why is this planning approach fundamentally misaligned with the client's stated objective?
Hard27What is the primary purpose of the 'Scope' section in the Rules of Engagement?
Easy28You are planning a penetration test for a financial institution that operates a large mainframe environment. The client wants to ensure that the test does not disrupt critical batch processing jobs. Which TWO of the following are the MOST important items to include in the Rules of Engagement (RoE) to address this concern? (Choose two.)
Hard29You are finalizing the Rules of Engagement (RoE) for a penetration test of a regional hospital network. The client's legal counsel requires that any testing activity be immediately suspended if a life-safety system is affected. Which element should you add to the RoE to satisfy this requirement?
Medium30You are planning an external penetration test for a financial services firm. The client's legal team wants assurance that the engagement can be defended if law enforcement or regulators inquire about the testing. Which TWO of the following should be included in the Rules of Engagement to provide this assurance? (Choose two.)
Medium31During planning for a penetration test, the client states the goal is to evaluate how well the security operations center detects and responds to attacker activity. Which engagement type best aligns with this objective?
EasyOther domains
All GPEN exam domains
Frequently asked questions
- What does the Pen Test Planning domain cover on the GPEN exam?
- Given a client scenario, identify the governing document, correct testing methodology, and whether authorization covers every target. The single most important thing: never test an asset without documented, written permission from the party that owns or hosts it.
- How many questions are in this domain?
- This page lists all 31 Pen Test Planning questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Pen Test Planning questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.