mediumMultiple Select
CISSP Practice Question: A security team is planning to conduct a social…
A security team is planning to conduct a social engineering test as part of an organization's security assessment. Which THREE of the following should be included in the test plan to ensure ethical and legal compliance?
⚠ Common exam trap
A common mix-up: candidates think 'obtain consent' is optional if the test is internal, or they may confuse 'informed consent' with 'blanket approval' and fail to recognize that explicit written consent from management is mandatory to avoid legal and ethical violations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtain explicit written consent from management
Option A is correct because obtaining explicit written consent from management establishes documented authorization, which is legally required before conducting any social engineering test and protects the testers from liability. Option C is correct because a prearranged stop word or abort mechanism lets targets halt the test immediately if it causes distress or escalates beyond acceptable limits, preserving participant welfare and ethical conduct. Option D is correct because defining clear scope and boundaries specifies which departments, techniques, and timeframes are permitted, preventing unauthorized actions and keeping the assessment within legal and contractual limits. Options B and E are incorrect: using real personal information of targets violates privacy principles and data protection regulations, and including all employees without exceptions ignores the need for scoping, consent, and exclusion of sensitive roles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Obtain explicit written consent from management
Why this is correct
Explicit written consent from management establishes documented authorisation before any pretexting or manipulation occurs, satisfying the legal requirement that the organisation's leadership approves the test. Without it, testers could face trespass or fraud claims regardless of intent.
- ✗
Use real personal information of targets
Why it's wrong here
Using genuine personal data of targets breaches data protection and privacy obligations, since social engineering tests should rely on fabricated or consented details. It is tempting because real information improves pretext credibility, yet a compliant plan uses synthetic personas and obtains written authorisation before any targeting.
- ✓
Have a stop word or abort mechanism
Why this is correct
A stop word or abort mechanism lets targets halt the test immediately if distress or operational impact occurs, satisfying the ethical duty to prevent harm. This safeguard ensures testers can withdraw instantly, preserving consent and limiting legal exposure during the engagement.
- ✓
Define clear scope and boundaries
Why this is correct
Defining clear scope and boundaries specifies which systems, staff and techniques are permitted, preventing testers from straying into unauthorised areas. This constraint directly satisfies the legal compliance requirement by keeping activity within agreed limits and documented authorisation.
- ✗
Include all employees without exceptions
Why it's wrong here
Testing every employee without exceptions breaches the requirement for a defined, authorised scope with agreed exclusions, such as executives or legal counsel. It is tempting because broad coverage maximises realism, but a compliant plan specifies a limited target list approved by management and legal.
Go deeper
Related to this question
Learn chapter
Disaster Recovery Planning
Key term
Privacy
Privacy in IT is the control over how personal data is collected, stored, used, and shared by systems and organizations.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.