Courseiva
Pen Test Planning →mediumMultiple Choice

GPEN Pen Test Planning Practice Question

You are the lead penetration tester for an engagement at a regional bank. The client's legal team has approved testing of their external IP range, but the Statement of Work does not mention the third-party core banking platform hosted by a vendor on a shared subnet. During reconnaissance, you discover that one of the client's external IPs routes directly into the vendor's shared environment. What is the MOST appropriate action before conducting any exploitation?

⚠ Common exam trap

The trap here is assuming that an IP appearing in the client's approved range automatically authorizes testing of whatever infrastructure that IP actually reaches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pause testing and obtain written authorization from both the client and the third-party vendor covering the shared environment.

Discovering that an in-scope IP routes into a third-party shared environment creates a legal scope conflict. The tester must halt activity on that asset and secure written authorization from both the client and the hosting vendor before any exploitation. This aligns with Rules of Engagement principles that require explicit consent for every tested system, especially third-party infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exploit the vulnerability but immediately notify the vendor after obtaining the initial shell to demonstrate impact.

    Why it's wrong here

    Exploiting first and notifying afterward still constitutes unauthorized access to third-party systems, regardless of intent. The notification does not retroactively grant permission. This approach exposes the tester and client to legal liability and violates the Rules of Engagement. Authorization must precede any exploitation of systems not covered by the existing written agreement.

  • ✓

    Pause testing and obtain written authorization from both the client and the third-party vendor covering the shared environment.

    Why this is correct

    The shared subnet belongs to a third party not named in the Statement of Work, so testing it without documented authorization risks violating the engagement's legal boundaries. Getting written permission from both the client and the vendor ensures the Rules of Engagement are expanded lawfully before any exploitation, protecting the tester, the client, and the hosted platform from unauthorized access claims.

  • ✗

    Document the finding as informational and skip any testing of that IP, moving on to other in-scope targets.

    Why it's wrong here

    Skipping the IP entirely forfeits a potentially critical finding and does not resolve the scope ambiguity. The correct professional response is to clarify and expand authorization, not to silently omit a discovered asset. Documenting as informational without client consultation may leave a real exposure unreported and fails to address the engagement's evolving boundaries.

  • ✗

    Continue testing because the IP address appears in the client's external range and was approved in the Statement of Work.

    Why it's wrong here

    Although the IP appears in the client's range, it routes into a vendor-owned shared environment, meaning exploitation would affect systems outside the authorized scope. Relying on the IP listing alone ignores that the actual target is third-party infrastructure. Proceeding could constitute unauthorized access and breach the engagement's legal terms, so this rationale is unsafe here.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.