Courseiva
Pen Test Planning →mediumMultiple Select

GPEN Pen Test Planning Practice Question

You are planning an external penetration test for a financial services firm. The client's legal team wants assurance that the engagement can be defended if law enforcement or regulators inquire about the testing. Which TWO of the following should be included in the Rules of Engagement to provide this assurance? (Choose two.)

⚠ Common exam trap

The trap here is assuming that detailed technical tooling or absolute non-disruption guarantees strengthen legal defensibility, when authorization and source identification are what actually matter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A list of authorized source IP addresses from which testing will originate.

Authorized source IP addresses and named client signatories are the two elements that most directly support legal defensibility. The source IPs let the client and authorities distinguish sanctioned traffic from real attacks, while the signatories establish a documented chain of authorization. Together they demonstrate that the activity was explicitly approved by authorized parties and originated from known, approved infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The penetration tester's personal home address and after-hours phone number.

    Why it's wrong here

    Contact information for the testing team is useful, but a tester's personal home address is not an appropriate or necessary element of the Rules of Engagement. Professional contact details such as a business phone and email suffice. Including personal information creates privacy risk and does not contribute to the legal defensibility of the engagement.

  • ✗

    A detailed exploit payload library the testers plan to use against production systems.

    Why it's wrong here

    While techniques may be discussed at a high level, providing a detailed exploit payload library is not a standard Rules of Engagement element and could expose sensitive tooling. Regulators care about authorization, scope, and boundaries, not the specific payloads. Including this adds unnecessary risk and does not strengthen the legal defensibility of the engagement.

  • ✓

    A list of authorized source IP addresses from which testing will originate.

    Why this is correct

    Listing the source IP addresses used by the testing team allows the client's security operations center and any external parties to distinguish authorized traffic from real attacks. If law enforcement or a third party detects the activity, the client can produce documentation showing those specific IPs were sanctioned. This is a standard element of defensible Rules of Engagement for external testing.

  • ✗

    A guarantee that no production system will experience any disruption during testing.

    Why it's wrong here

    No responsible penetration test can guarantee zero disruption, especially when testing production systems. Rules of Engagement typically include risk acknowledgment and rollback procedures rather than absolute guarantees. Promising no disruption would be misleading and could expose the testing firm to liability if an unexpected outage occurred during authorized activities.

  • ✓

    The names and contact details of the client's authorized signatories who approved the test.

    Why this is correct

    Identifying the individuals who signed off on the engagement establishes the chain of authorization. If a regulator or law enforcement agency questions whether the testing was sanctioned, the client can demonstrate that specific, named officers with authority approved the activity. Without this, the engagement lacks a provable authorization trail, weakening any legal defense.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.