Courseiva
Pen Test Planning →easyMultiple Choice

GPEN Pen Test Planning Practice Question

Which document is primarily responsible for defining the 'Rules of Engagement' (RoE) in a penetration testing project?

⚠ Common exam trap

Candidates often confuse the Rules of Engagement (RoE) with the Statement of Work (SOW) or the legal contract, failing to recognize the RoE as the specific document governing technical testing procedures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Rules of Engagement (RoE) document.

The Rules of Engagement document serves as the operational handbook for the penetration test, detailing exactly what is permitted, what is prohibited, and the emergency procedures to follow. It bridges the gap between the legal contract and the technical execution, ensuring that all parties have a mutual understanding of the engagement's boundaries, safety protocols, and professional expectations, which is critical for minimizing risks during testing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Statement of Work (SOW).

    Why it's wrong here

    The SOW outlines the business objectives, deliverables, timelines, and costs of the engagement. While it may reference the RoE, it does not contain the specific technical constraints, emergency protocols, and operational safety rules that define the day-to-day execution of the penetration test as the RoE document does.

  • ✓

    The Rules of Engagement (RoE) document.

    Why this is correct

    The RoE document is specifically created to define the operational parameters of the assessment. It details the scope, prohibited actions, communication protocols, and escalation procedures, providing the technical team with a clear set of guidelines to follow while performing the assessment to ensure safety and compliance.

  • ✗

    The Non-Disclosure Agreement (NDA).

    Why it's wrong here

    The NDA is a legal contract that governs the handling of confidential information between the client and the tester. It does not contain any technical information regarding the penetration test, nor does it define the scope or the operational procedures required to conduct the security assessment safely.

  • ✗

    The Service Level Agreement (SLA).

    Why it's wrong here

    An SLA is typically used to define the expected level of service, uptime, and performance metrics between a service provider and a customer. It is irrelevant to the penetration testing process, as it does not address the security, scope, or operational procedures required for conducting a penetration test.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.