GPEN Pen Test Planning Practice Question
During the planning phase of a penetration test for a multinational corporation, you discover that the client's legal department requires all testing activities to comply with the laws of each country where their offices are located. The client has offices in Germany, Brazil, and Japan. Which of the following is the MOST important consideration when planning the engagement?
⚠ Common exam trap
The trap here is assuming that a single authorization letter or centralized testing location can bypass the need to comply with diverse international laws.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure that testing does not violate any local laws regarding unauthorized access, even if the client has authorized it.
The most important consideration is ensuring that testing activities comply with the local laws of each country where targets reside. Client authorization does not override local criminal laws. A thorough legal review and, if necessary, local legal counsel are essential to avoid criminal liability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform all testing from a central location in the client's home country to avoid international legal issues.
Why it's wrong here
The location of the tester does not determine which laws apply; the location of the target systems and the nationality of the parties involved matter. Testing from a central location does not exempt the tester from complying with the laws of the countries where the targets reside.
- ✗
Use only automated tools that are approved by the client's legal department in each country.
Why it's wrong here
Tool approval is not the primary legal concern. Even with approved tools, the act of testing itself must comply with local laws. Legal compliance involves authorization, data handling, and reporting requirements, not just the choice of tools.
- ✗
Obtain a single global authorization letter from the client's headquarters that covers all offices.
Why it's wrong here
A single global authorization may not be recognized in all jurisdictions. Some countries require specific formats or local signatures, and a headquarters letter might not satisfy local legal requirements. Relying solely on it could leave the tester unprotected under local laws.
- ✓
Ensure that testing does not violate any local laws regarding unauthorized access, even if the client has authorized it.
Why this is correct
In some countries, unauthorized access laws may apply even with client authorization if the tester is not physically present or if the authorization does not meet local legal requirements. For example, Germany has strict computer crime laws. Testing must be planned to comply with each jurisdiction's legal framework to avoid criminal liability for the tester and the client.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.