Courseiva
Pen Test Planning →mediumMultiple Select

GPEN Pen Test Planning Practice Question

When planning for an engagement involving sensitive data, which TWO of the following must be included in the data handling plan?

⚠ Common exam trap

Test-takers frequently focus only on data collection during a pentest while forgetting the critical post-engagement requirement of secure data destruction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The encryption standards for data at rest and in transit.

Data handling is paramount when managing sensitive information during a penetration test. The tester must ensure that data is encrypted at rest and in transit, and that it is securely destroyed once the project concludes. These protocols protect the client from data breaches caused by the testing activity itself, maintaining the integrity and confidentiality of the sensitive information processed during the course of the engagement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The encryption standards for data at rest and in transit.

    Why this is correct

    Specifying the encryption standards ensures that the sensitive data collected during the test is protected from unauthorized access at all times. By documenting these standards, both the client and the tester agree on the security measures required to protect the information throughout the duration of the engagement.

  • ✗

    The public keys of all developers involved in the project.

    Why it's wrong here

    Public keys are meant for encryption, but there is no need to list them in a data handling plan. The plan should focus on the procedures and policies for securing the data itself, rather than managing the cryptographic assets of the personnel involved in the development process.

  • ✓

    A secure, verifiable process for the destruction of client data.

    Why this is correct

    A verifiable destruction process is critical to ensure that client data does not remain on the tester's systems after the engagement. This protects the client's information from future breaches and ensures compliance with the data retention policies agreed upon in the contract or the data handling plan.

  • ✗

    The names of all servers used to store the data.

    Why it's wrong here

    Listing the specific names of servers in a data handling plan provides unnecessary operational information that could become an attack vector if the plan itself is compromised. The focus should be on the security controls, such as encryption and retention policies, not on the physical or logical server names.

  • ✗

    A list of all public websites the testers use for research.

    Why it's wrong here

    Researching public websites is a standard part of the testing process, but it has nothing to do with the data handling plan for sensitive client data. Including such a list is irrelevant and does not address the security requirements for protecting the client's confidential information during the project.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.