GPEN Vulnerability Scanning Practice Question
Which document should a penetration tester consult to determine the allowed scope and rules of engagement for a vulnerability scan?
⚠ Common exam trap
Candidates often confuse the Rules of Engagement with technical configuration guides or general security policies like a vulnerability management policy, forgetting that RoE specifically governs the operational boundaries and legal permissions for testing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Rules of Engagement (RoE) document.
The Rules of Engagement (RoE) or Statement of Work (SOW) defines the legal and operational boundaries of the assessment. It specifies which systems are in scope, which are out of scope, and what scanning techniques are permitted. Adhering to these documents is essential for maintaining compliance and avoiding unauthorized actions that could lead to legal repercussions or unintended service disruption during the testing phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The organization's public-facing bug bounty program policy.
Why it's wrong here
Bug bounty policies are designed for external researchers and usually lack the specific internal scoping, sensitivity thresholds, and legal protections required for a professional penetration test. They are not a substitute for a formal, project-specific Rules of Engagement document for a internal security assessment.
- ✓
The Rules of Engagement (RoE) document.
Why this is correct
The Rules of Engagement document outlines the authorized scope, permitted testing times, and specific constraints for the engagement. It is the primary legal and operational guide that dictates how the tester can interact with the client's assets during a vulnerability assessment.
- ✗
The vendor's hardware specification sheets.
Why it's wrong here
Hardware specifications provide technical details about system components but do not contain information about the legal or operational rules for a security assessment. Consulting these would be helpful for understanding the hardware, but it would not provide any guidance on the permitted testing scope.
- ✗
The latest version of the Common Vulnerabilities and Exposures (CVE) list.
Why it's wrong here
The CVE list provides definitions of known vulnerabilities but contains no operational or legal guidance for conducting a penetration test. It is a technical resource used for identifying vulnerabilities, not for governing the conduct or scope of a professional security assessment.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.