Courseiva
mediumMultiple Select

CISSP Practice Question: A security team is planning to conduct a social…

A security team is planning to conduct a social engineering test as part of an organization's security assessment. Which THREE of the following should be included in the test plan to ensure ethical and legal compliance?

⚠ Common exam trap

A common mix-up: candidates think 'obtain consent' is optional if the test is internal, or they may confuse 'informed consent' with 'blanket approval' and fail to recognize that explicit written consent from management is mandatory to avoid legal and ethical violations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Obtain explicit written consent from management

Option A is correct because obtaining explicit written consent from management establishes documented authorization, which is legally required before conducting any social engineering test and protects the testers from liability. Option C is correct because a prearranged stop word or abort mechanism lets targets halt the test immediately if it causes distress or escalates beyond acceptable limits, preserving participant welfare and ethical conduct. Option D is correct because defining clear scope and boundaries specifies which departments, techniques, and timeframes are permitted, preventing unauthorized actions and keeping the assessment within legal and contractual limits. Options B and E are incorrect: using real personal information of targets violates privacy principles and data protection regulations, and including all employees without exceptions ignores the need for scoping, consent, and exclusion of sensitive roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Obtain explicit written consent from management

    Why this is correct

    Explicit written consent from management establishes documented authorisation before any pretexting or manipulation occurs, satisfying the legal requirement that the organisation's leadership approves the test. Without it, testers could face trespass or fraud claims regardless of intent.

  • ✗

    Use real personal information of targets

    Why it's wrong here

    Using genuine personal data of targets breaches data protection and privacy obligations, since social engineering tests should rely on fabricated or consented details. It is tempting because real information improves pretext credibility, yet a compliant plan uses synthetic personas and obtains written authorisation before any targeting.

  • ✓

    Have a stop word or abort mechanism

    Why this is correct

    A stop word or abort mechanism lets targets halt the test immediately if distress or operational impact occurs, satisfying the ethical duty to prevent harm. This safeguard ensures testers can withdraw instantly, preserving consent and limiting legal exposure during the engagement.

  • ✓

    Define clear scope and boundaries

    Why this is correct

    Defining clear scope and boundaries specifies which systems, staff and techniques are permitted, preventing testers from straying into unauthorised areas. This constraint directly satisfies the legal compliance requirement by keeping activity within agreed limits and documented authorisation.

  • ✗

    Include all employees without exceptions

    Why it's wrong here

    Testing every employee without exceptions breaches the requirement for a defined, authorised scope with agreed exclusions, such as executives or legal counsel. It is tempting because broad coverage maximises realism, but a compliant plan specifies a limited target list approved by management and legal.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.