GPEN Pen Test Planning Practice Question
You are drafting the Rules of Engagement (RoE) for a penetration test of a client's internal network. The client wants to ensure that the engagement is legally sound and that all parties understand their responsibilities. Which TWO of the following items are essential to include in the RoE? (Choose two.)
⚠ Common exam trap
Candidates often confuse the Rules of Engagement with a Statement of Work or a technical testing plan, leading to inclusion of non-essential items.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Explicit written authorization from the client to perform the test.
The two essential items are explicit written authorization and emergency contact information. Written authorization provides legal protection and confirms consent, while emergency contacts ensure rapid response to incidents. These elements are fundamental to a legally sound and operationally safe penetration test, distinguishing the RoE from other planning documents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Explicit written authorization from the client to perform the test.
Why this is correct
Written authorization is a legal necessity to protect the tester from liability and to prove that the client consented to the testing. It should specify the scope, time frame, and any limitations. Without it, the tester could be considered to be conducting unauthorized access, which is illegal. This is a fundamental element of the Rules of Engagement and is required for any professional penetration test.
- ✗
A statement of work (SOW) detailing the deliverables and timeline.
Why it's wrong here
The SOW is typically a separate contractual document that outlines deliverables, timeline, and costs. While it is important, it is not an essential element of the Rules of Engagement, which focuses on the operational and legal boundaries of the testing. The RoE should reference the SOW but does not need to duplicate it. Including the SOW in the RoE could cause confusion and is not a standard requirement.
- ✓
Emergency contact information for both the client and the testing team.
Why this is correct
Emergency contacts are essential for quickly addressing incidents, such as accidental disruption or discovery of a critical vulnerability. The RoE should include names, phone numbers, and escalation procedures. This ensures that if something goes wrong, both parties can communicate immediately to mitigate impact. It is a critical operational and legal safeguard, especially in sensitive environments where downtime or data loss is a concern.
- ✗
A list of all vulnerabilities that will be tested.
Why it's wrong here
Listing specific vulnerabilities is impractical and not part of the RoE. The RoE defines the boundaries and rules, not the technical details of what will be tested. Penetration testing is exploratory; testers may discover unexpected vulnerabilities. Including a list of vulnerabilities would limit the test and is not essential for legal or operational clarity. The scope should define target systems, not vulnerabilities.
- ✗
The specific tools and techniques that will be used during the test.
Why it's wrong here
While the client may want to know the general approach, specifying exact tools and techniques is not essential in the RoE. It can constrain the tester and may become outdated. The RoE should focus on rules, boundaries, and legal agreements. Technical details are usually covered in the testing plan or methodology document, not the RoE. Including them could also reveal sensitive information if the RoE is shared widely.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.