Courseiva

GPEN · domain

Pen Test Planning

The Pen Test Planning domain covers scoping, legal authorization, and engagement design before any exploitation begins. GPEN questions present client scenarios and ask you to select the correct document, testing methodology, or escalation path. Expect to reason about Rules of Engagement, authorization boundaries, third-party hosting, and how target knowledge shapes test design and reporting.

31 questions6 easy17 medium8 hard

Focused practice

Practice Pen Test Planning questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Pen Test Planning

Given a client scenario, identify the governing document, correct testing methodology, and whether authorization covers every target. The single most important thing: never test an asset without documented, written permission from the party that owns or hosts it.

Rules of Engagement defining scope, authorized targets, time windows, and emergency contacts

Black-box, gray-box, and white-box methodologies and the target knowledge each provides

Written authorization and third-party cloud hosting consent before testing external assets

Scoping statements of work that bound IP ranges, applications, and testing limitations

Watch out for

Common Pen Test Planning exam traps

  • ▸Treating a verbal go-ahead or email as sufficient authorization when written permission from the asset owner is required
  • ▸Confusing gray-box (partial knowledge) with black-box (zero knowledge) when the scenario describes credentials or documentation provided
  • ▸Ignoring third-party cloud provider restrictions and testing hosted assets without the provider's written consent

Question index

All Pen Test Planning questions (31)

Click any question to see the full explanation, or start a practice session above.

1

A client asks you to perform a penetration test on their internal network. During the planning phase, they provide you with a list of IP addresses and ask you to sign a document that limits your testing to those addresses. Which of the following best describes the purpose of this document?

Easy
2

During the planning phase of a penetration test for a multinational corporation, you discover that the client's legal department requires all testing activities to comply with the laws of each country where their offices are located. The client has offices in Germany, Brazil, and Japan. Which of the following is the MOST important consideration when planning the engagement?

Hard
3

You are drafting the Rules of Engagement (RoE) for a penetration test of a client's internal network. The client wants to ensure that the engagement is legally sound and that all parties understand their responsibilities. Which TWO of the following items are essential to include in the RoE? (Choose two.)

Medium
4

A software-as-a-service provider engages your team for a penetration test of its production environment. The client wants testing to occur during business hours so its engineers can observe. Which planning consideration is MOST important to address in the Rules of Engagement before testing begins?

Medium
5

You are the lead penetration tester for a financial services client. During the scoping meeting, the client states they want to test their external perimeter but are concerned about accidental disruption to production trading systems. They ask you to propose a testing approach that minimizes operational risk while still validating exploitable vulnerabilities. Which of the following is the MOST appropriate recommendation?

Medium
6

A client asks for an 'unannounced' penetration test to test their incident response team. What is the most important preparatory step before commencing this exercise?

Medium
7

You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to ensure that any protected health information (PHI) accessed during testing is handled securely. Which of the following is the MOST critical element to include in the data handling plan?

Hard
8

Refer to the exhibit. You are currently at 17:15. You have just identified a critical, easily exploitable vulnerability on 10.1.1.20. What is the correct next step?

Hard
9

You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to test a new patient portal hosted on AWS. During the kickoff meeting, the client's legal team asks how you will handle any protected health information (PHI) that you might encounter. Which of the following is the most appropriate action to take before testing begins?

Medium
10

When planning for an engagement involving sensitive data, which TWO of the following must be included in the data handling plan?

Medium
11

If a penetration tester discovers a vulnerability that could compromise a third-party hosted service during an engagement, what is the correct professional responsibility?

Medium
12

A healthcare client hires your team for an internal penetration test. During the kickoff meeting, the client's compliance officer asks which document formally defines the specific systems, time windows, and testing techniques that are authorized for the engagement. Which document should you reference?

Easy
13

A financial services client engages you for an external penetration test and wants contractual protection before testing begins. Which TWO items belong in a master services agreement or statement of work to limit the firm's legal exposure while authorizing the work? (Choose two.)

Hard
14

Refer to the exhibit. You are performing a penetration test based on this policy. You discover an unpatched SQL injection vulnerability on 192.168.10.20 that could be used to trigger a database lock-up. What is the most appropriate course of action?

Hard
15

You are planning a penetration test for a client with a large wireless network. The client wants to assess the security of their WPA3-Enterprise deployment. Which of the following should be included in the Rules of Engagement to address the risk of disrupting legitimate wireless users?

Medium
16

During the scoping phase of a penetration test for a global e-commerce client, you identify that the client uses a cloud-based Content Delivery Network (CDN) to host static assets. Which action is the most critical for ensuring the engagement remains within the Rules of Engagement (RoE)?

Medium
17

Which document is primarily responsible for defining the 'Rules of Engagement' (RoE) in a penetration testing project?

Easy
18

You are planning a penetration test for a client that has a hybrid cloud environment. The client's security team wants to ensure that the test does not violate the shared responsibility model of their cloud provider. Which of the following should you do FIRST to align the test with the cloud provider's policies?

Medium
19

You are the lead penetration tester for an engagement at a regional bank. The client's legal team has approved testing of their external IP range, but the Statement of Work does not mention the third-party core banking platform hosted by a vendor on a shared subnet. During reconnaissance, you discover that one of the client's external IPs routes directly into the vendor's shared environment. What is the MOST appropriate action before conducting any exploitation?

Medium
20

During planning, a client requests that you use a specific automated scanner that is known to produce false positives and potential system instability. What is the most professional way to handle this request?

Medium
21

During a penetration test for a multinational retailer, you discover that a legacy internal application in scope contains a hardcoded credential that also grants access to a payment processing system the client explicitly excluded from testing. You have not yet used the credential. What is the MOST appropriate course of action?

Hard
22

When defining the 'Scope' for a penetration test, which THREE factors are critical to document to ensure the engagement is legally and operationally sound?

Medium
23

You are drafting the Rules of Engagement for an internal penetration test. Which TWO of the following items are considered mandatory for the 'Communication Plan' section?

Medium
24

Which of the following best describes the 'Gray-box' testing methodology?

Medium
25

A client asks you to perform a penetration test on their web application. During the planning phase, they mention that the application is hosted on a third-party cloud provider and they do not have written permission from the provider to test the underlying infrastructure. What is the MOST appropriate action?

Easy
26

An enterprise client insists on a blind 'black-box' penetration test where the testing team receives zero prior knowledge regarding network architecture, IP ranges, or applications. However, the client's primary objective is to thoroughly test deep-seated business logic vulnerabilities within a critical custom web application. Why is this planning approach fundamentally misaligned with the client's stated objective?

Hard
27

What is the primary purpose of the 'Scope' section in the Rules of Engagement?

Easy
28

You are planning a penetration test for a financial institution that operates a large mainframe environment. The client wants to ensure that the test does not disrupt critical batch processing jobs. Which TWO of the following are the MOST important items to include in the Rules of Engagement (RoE) to address this concern? (Choose two.)

Hard
29

You are finalizing the Rules of Engagement (RoE) for a penetration test of a regional hospital network. The client's legal counsel requires that any testing activity be immediately suspended if a life-safety system is affected. Which element should you add to the RoE to satisfy this requirement?

Medium
30

You are planning an external penetration test for a financial services firm. The client's legal team wants assurance that the engagement can be defended if law enforcement or regulators inquire about the testing. Which TWO of the following should be included in the Rules of Engagement to provide this assurance? (Choose two.)

Medium
31

During planning for a penetration test, the client states the goal is to evaluate how well the security operations center detects and responds to attacker activity. Which engagement type best aligns with this objective?

Easy

Frequently asked questions

What does the Pen Test Planning domain cover on the GPEN exam?
Given a client scenario, identify the governing document, correct testing methodology, and whether authorization covers every target. The single most important thing: never test an asset without documented, written permission from the party that owns or hosts it.
How many questions are in this domain?
This page lists all 31 Pen Test Planning questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Pen Test Planning questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN pen test planning Practice Questions