GPEN Pen Test Planning Practice Question
You are the lead penetration tester for an engagement at a regional bank. The client's legal team has approved testing of their external IP range, but the Statement of Work does not mention the third-party core banking platform hosted by a vendor on a shared subnet. During reconnaissance, you discover that one of the client's external IPs routes directly into the vendor's shared environment. What is the MOST appropriate action before conducting any exploitation?
⚠ Common exam trap
The trap here is assuming that an IP appearing in the client's approved range automatically authorizes testing of whatever infrastructure that IP actually reaches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pause testing and obtain written authorization from both the client and the third-party vendor covering the shared environment.
Discovering that an in-scope IP routes into a third-party shared environment creates a legal scope conflict. The tester must halt activity on that asset and secure written authorization from both the client and the hosting vendor before any exploitation. This aligns with Rules of Engagement principles that require explicit consent for every tested system, especially third-party infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exploit the vulnerability but immediately notify the vendor after obtaining the initial shell to demonstrate impact.
Why it's wrong here
Exploiting first and notifying afterward still constitutes unauthorized access to third-party systems, regardless of intent. The notification does not retroactively grant permission. This approach exposes the tester and client to legal liability and violates the Rules of Engagement. Authorization must precede any exploitation of systems not covered by the existing written agreement.
- ✓
Pause testing and obtain written authorization from both the client and the third-party vendor covering the shared environment.
Why this is correct
The shared subnet belongs to a third party not named in the Statement of Work, so testing it without documented authorization risks violating the engagement's legal boundaries. Getting written permission from both the client and the vendor ensures the Rules of Engagement are expanded lawfully before any exploitation, protecting the tester, the client, and the hosted platform from unauthorized access claims.
- ✗
Document the finding as informational and skip any testing of that IP, moving on to other in-scope targets.
Why it's wrong here
Skipping the IP entirely forfeits a potentially critical finding and does not resolve the scope ambiguity. The correct professional response is to clarify and expand authorization, not to silently omit a discovered asset. Documenting as informational without client consultation may leave a real exposure unreported and fails to address the engagement's evolving boundaries.
- ✗
Continue testing because the IP address appears in the client's external range and was approved in the Statement of Work.
Why it's wrong here
Although the IP appears in the client's range, it routes into a vendor-owned shared environment, meaning exploitation would affect systems outside the authorized scope. Relying on the IP listing alone ignores that the actual target is third-party infrastructure. Proceeding could constitute unauthorized access and breach the engagement's legal terms, so this rationale is unsafe here.
Visual reference
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.