A client asks you to perform a penetration test on their internal network. During the planning phase, they provide you with a list of IP addresses and ask you to sign a document that limits your testing to those addresses. Which of the following best describes the purpose of this document?
This document is a scope agreement and authorization letter. It ensures that the tester only targets the agreed-upon IP addresses, protecting both parties legally. Testing outside this scope could be considered unauthorized access, even if the client verbally approved a broader range. It is a fundamental component of the Rules of Engagement.
Why this answer
The document is a scope and authorization agreement. It legally permits testing only on specified IP addresses and protects both parties by clearly defining what is allowed. Without it, testing could be deemed unauthorized, leading to legal consequences.
Exam trap
The trap here is confusing a scope authorization document with other legal agreements like NDAs or liability waivers, which serve different purposes.