Courseiva
Pen Test Planning →mediumMultiple Choice

GPEN Pen Test Planning Practice Question

You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to test a new patient portal hosted on AWS. During the kickoff meeting, the client's legal team asks how you will handle any protected health information (PHI) that you might encounter. Which of the following is the most appropriate action to take before testing begins?

⚠ Common exam trap

The trap here is assuming that technical safeguards like encryption or synthetic data can substitute for the legal requirement of a Business Associate Agreement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign a Business Associate Agreement (BAA) with the client and ensure your testing infrastructure is covered under it.

Under HIPAA, a penetration tester acting as a business associate must sign a BAA before accessing systems that may contain PHI. This agreement establishes permissible uses and safeguards for protected health information. Without it, the engagement could be non-compliant regardless of technical precautions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypt all test data at rest and in transit, and avoid accessing any real patient data by using synthetic records.

    Why it's wrong here

    Encryption and synthetic data are good practices, but they do not replace the legal requirement for a BAA when a business associate may access PHI. Even with strong technical controls, if real PHI is encountered, the lack of a BAA is a compliance violation. The question asks for the most appropriate action before testing begins.

  • ✓

    Sign a Business Associate Agreement (BAA) with the client and ensure your testing infrastructure is covered under it.

    Why this is correct

    A BAA is required under HIPAA whenever a covered entity shares PHI with a business associate, including a penetration tester. By signing a BAA, you contractually agree to safeguard PHI and are legally permitted to access it during testing. Ensuring your infrastructure is covered prevents gaps if data is stored or processed on your systems.

  • ✗

    Obtain written authorization from the client's CEO and proceed with testing without additional agreements.

    Why it's wrong here

    While written authorization is essential for penetration testing, it does not fulfill HIPAA requirements for handling PHI. A CEO's authorization alone does not establish the legal safeguards required when a third party accesses protected health information. Without a BAA, the engagement could violate HIPAA and expose both parties to penalties.

  • ✗

    Conduct the test only after hours to minimize the risk of encountering live patient data.

    Why it's wrong here

    Testing after hours does not eliminate the possibility of encountering PHI, nor does it satisfy HIPAA's contractual requirements. Timing is an operational consideration, but it does not address the legal obligation to have a BAA in place. The client's legal team is concerned with compliance, not just risk reduction.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.