Courseiva

GPEN · topic practice

Pen Test Planning practice questions

The Pen Test Planning domain covers scoping, legal authorization, and engagement design before any exploitation begins. GPEN questions present client scenarios and ask you to select the correct document, testing methodology, or escalation path. Expect to reason about Rules of Engagement, authorization boundaries, third-party hosting, and how target knowledge shapes test design and reporting.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Pen Test Planning

What the exam tests

What to know about Pen Test Planning

Given a client scenario, identify the governing document, correct testing methodology, and whether authorization covers every target. The single most important thing: never test an asset without documented, written permission from the party that owns or hosts it.

Rules of Engagement defining scope, authorized targets, time windows, and emergency contacts

Black-box, gray-box, and white-box methodologies and the target knowledge each provides

Written authorization and third-party cloud hosting consent before testing external assets

Scoping statements of work that bound IP ranges, applications, and testing limitations

Watch out for

Common Pen Test Planning exam traps

  • ▸Treating a verbal go-ahead or email as sufficient authorization when written permission from the asset owner is required
  • ▸Confusing gray-box (partial knowledge) with black-box (zero knowledge) when the scenario describes credentials or documentation provided
  • ▸Ignoring third-party cloud provider restrictions and testing hosted assets without the provider's written consent

Practice set

Pen Test Planning questions

20 questions · select your answer, then reveal the explanation

An enterprise client insists on a blind 'black-box' penetration test where the testing team receives zero prior knowledge regarding network architecture, IP ranges, or applications. However, the client's primary objective is to thoroughly test deep-seated business logic vulnerabilities within a critical custom web application. Why is this planning approach fundamentally misaligned with the client's stated objective?

During the scoping phase of a penetration test for a global e-commerce client, you identify that the client uses a cloud-based Content Delivery Network (CDN) to host static assets. Which action is the most critical for ensuring the engagement remains within the Rules of Engagement (RoE)?

You are drafting the Rules of Engagement for an internal penetration test. Which TWO of the following items are considered mandatory for the 'Communication Plan' section?

Refer to the exhibit. You are performing a penetration test based on this policy. You discover an unpatched SQL injection vulnerability on 192.168.10.20 that could be used to trigger a database lock-up. What is the most appropriate course of action?

Exhibit

TARGET_POLICY: { "Scope": ["192.168.10.0/24"], "Exclusions": ["192.168.10.50"], "Methodology": "Black-box", "Testing_Window": "2023-10-01 to 2023-10-05", "Allowed_Attacks": ["Injection", "XSS"], "Forbidden_Attacks": ["DoS", "Social_Engineering"] }

Which document is primarily responsible for defining the 'Rules of Engagement' (RoE) in a penetration testing project?

During planning, a client requests that you use a specific automated scanner that is known to produce false positives and potential system instability. What is the most professional way to handle this request?

When defining the 'Scope' for a penetration test, which THREE factors are critical to document to ensure the engagement is legally and operationally sound?

A client asks for an 'unannounced' penetration test to test their incident response team. What is the most important preparatory step before commencing this exercise?

Refer to the exhibit. You are currently at 17:15. You have just identified a critical, easily exploitable vulnerability on 10.1.1.20. What is the correct next step?

Exhibit

CLIENT_CONFIG: { "Targets": ["10.1.1.0/24"], "Blacklist": ["10.1.1.5"], "Testing_Time": "08:00 - 17:00", "Reporting": "Weekly", "Escalation": "Emergency_Contact_Form" }
Question 10mediummultiple choice
Read the full Pen Test Planning explanation →

Which of the following best describes the 'Gray-box' testing methodology?

What is the primary purpose of the 'Scope' section in the Rules of Engagement?

Question 12mediummultiple choice
Read the full Pen Test Planning explanation →

If a penetration tester discovers a vulnerability that could compromise a third-party hosted service during an engagement, what is the correct professional responsibility?

When planning for an engagement involving sensitive data, which TWO of the following must be included in the data handling plan?

Question 14mediummultiple choice
Read the full Pen Test Planning explanation →

You are finalizing the Rules of Engagement (RoE) for a penetration test of a regional hospital network. The client's legal counsel requires that any testing activity be immediately suspended if a life-safety system is affected. Which element should you add to the RoE to satisfy this requirement?

A financial services client engages you for an external penetration test and wants contractual protection before testing begins. Which TWO items belong in a master services agreement or statement of work to limit the firm's legal exposure while authorizing the work? (Choose two.)

During planning for a penetration test, the client states the goal is to evaluate how well the security operations center detects and responds to attacker activity. Which engagement type best aligns with this objective?

Question 17mediummultiple choice
Read the full Pen Test Planning explanation →

You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to test a new patient portal hosted on AWS. During the kickoff meeting, the client's legal team asks how you will handle any protected health information (PHI) that you might encounter. Which of the following is the most appropriate action to take before testing begins?

You are planning a penetration test for a financial institution that operates a large mainframe environment. The client wants to ensure that the test does not disrupt critical batch processing jobs. Which TWO of the following are the MOST important items to include in the Rules of Engagement (RoE) to address this concern? (Choose two.)

Question 19mediummultiple choice
Read the full Pen Test Planning explanation →

You are the lead penetration tester for a financial services client. During the scoping meeting, the client states they want to test their external perimeter but are concerned about accidental disruption to production trading systems. They ask you to propose a testing approach that minimizes operational risk while still validating exploitable vulnerabilities. Which of the following is the MOST appropriate recommendation?

A client asks you to perform a penetration test on their internal network. During the planning phase, they provide you with a list of IP addresses and ask you to sign a document that limits your testing to those addresses. Which of the following best describes the purpose of this document?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Pen Test Planning sessions

Start a Pen Test Planning only practice session

Every question in these sessions is drawn from the Pen Test Planning domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Pen Test Planning?
Given a client scenario, identify the governing document, correct testing methodology, and whether authorization covers every target. The single most important thing: never test an asset without documented, written permission from the party that owns or hosts it.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Pen Test Planning questions in a focused session?
Yes — the session launcher on this page draws every question from the Pen Test Planning domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.