GPEN Pen Test Planning Practice Question
You are planning an external penetration test for a financial services firm. The client's legal team wants assurance that the engagement can be defended if law enforcement or regulators inquire about the testing. Which TWO of the following should be included in the Rules of Engagement to provide this assurance? (Choose two.)
⚠ Common exam trap
The trap here is assuming that detailed technical tooling or absolute non-disruption guarantees strengthen legal defensibility, when authorization and source identification are what actually matter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A list of authorized source IP addresses from which testing will originate.
Authorized source IP addresses and named client signatories are the two elements that most directly support legal defensibility. The source IPs let the client and authorities distinguish sanctioned traffic from real attacks, while the signatories establish a documented chain of authorization. Together they demonstrate that the activity was explicitly approved by authorized parties and originated from known, approved infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The penetration tester's personal home address and after-hours phone number.
Why it's wrong here
Contact information for the testing team is useful, but a tester's personal home address is not an appropriate or necessary element of the Rules of Engagement. Professional contact details such as a business phone and email suffice. Including personal information creates privacy risk and does not contribute to the legal defensibility of the engagement.
- ✗
A detailed exploit payload library the testers plan to use against production systems.
Why it's wrong here
While techniques may be discussed at a high level, providing a detailed exploit payload library is not a standard Rules of Engagement element and could expose sensitive tooling. Regulators care about authorization, scope, and boundaries, not the specific payloads. Including this adds unnecessary risk and does not strengthen the legal defensibility of the engagement.
- ✓
A list of authorized source IP addresses from which testing will originate.
Why this is correct
Listing the source IP addresses used by the testing team allows the client's security operations center and any external parties to distinguish authorized traffic from real attacks. If law enforcement or a third party detects the activity, the client can produce documentation showing those specific IPs were sanctioned. This is a standard element of defensible Rules of Engagement for external testing.
- ✗
A guarantee that no production system will experience any disruption during testing.
Why it's wrong here
No responsible penetration test can guarantee zero disruption, especially when testing production systems. Rules of Engagement typically include risk acknowledgment and rollback procedures rather than absolute guarantees. Promising no disruption would be misleading and could expose the testing firm to liability if an unexpected outage occurred during authorized activities.
- ✓
The names and contact details of the client's authorized signatories who approved the test.
Why this is correct
Identifying the individuals who signed off on the engagement establishes the chain of authorization. If a regulator or law enforcement agency questions whether the testing was sanctioned, the client can demonstrate that specific, named officers with authority approved the activity. Without this, the engagement lacks a provable authorization trail, weakening any legal defense.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.