GPEN Pen Test Planning Practice Question
You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to ensure that any protected health information (PHI) accessed during testing is handled securely. Which of the following is the MOST critical element to include in the data handling plan?
⚠ Common exam trap
The trap here is equating an NDA with adequate data protection, when HIPAA requires specific technical safeguards for PHI.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A detailed procedure for encrypting any extracted PHI and securely destroying it after the engagement.
The most critical element is a procedure for encrypting extracted PHI and securely destroying it after the engagement. This directly addresses HIPAA requirements for protecting PHI and minimizes the risk of unauthorized disclosure. Other elements like NDAs, scope, and scheduling are important but do not provide the necessary technical safeguards for PHI encountered during testing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A schedule of testing activities to avoid peak business hours.
Why it's wrong here
Scheduling testing during off-peak hours reduces operational impact but does not address the secure handling of PHI. It is a logistical consideration, not a data protection measure. The question focuses on handling PHI securely, which requires encryption and destruction procedures. While scheduling can be part of the plan, it is secondary to the specific safeguards needed for PHI under HIPAA.
- ✗
A list of all IP addresses and hostnames that are in scope for testing.
Why it's wrong here
Scope definition is essential for a penetration test, but it does not address how PHI will be handled if encountered. The question specifically asks about data handling for PHI. While scope helps prevent testing outside authorized boundaries, it does not provide safeguards for the confidentiality and integrity of PHI. Therefore, it is not the most critical element for the data handling plan in this context.
- ✓
A detailed procedure for encrypting any extracted PHI and securely destroying it after the engagement.
Why this is correct
Under HIPAA, PHI must be protected with appropriate administrative, physical, and technical safeguards. If testers extract PHI as proof of vulnerability, they must encrypt it in transit and at rest, and securely destroy it when no longer needed. This procedure directly addresses the confidentiality and security of PHI, making it the most critical element. It ensures compliance and reduces the risk of a data breach during the penetration test.
- ✗
A requirement that all testers sign a non-disclosure agreement (NDA) before testing begins.
Why it's wrong here
An NDA is important for legal protection but does not specify how PHI will be securely handled during testing. It addresses confidentiality obligations but not the technical and procedural safeguards required for PHI, such as encryption, access controls, and secure destruction. While NDAs are a component of the overall engagement, they are not the most critical element for secure data handling under HIPAA.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.