easyMultiple SelectObjective-mapped
CISSP Practice Question: Is planning a penetration test of its internal…
An organization is planning a penetration test of its internal network. Which TWO of the following are essential elements to include in the test scope and rules of engagement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Time windows when testing is permitted (e.g., after business hours).
The rules of engagement (ROE) and scope define the boundaries of the penetration test. Essential elements include authorized time windows (option B) to minimize business disruption and ensure testing occurs during agreed-upon periods, and a list of authorized IP addresses and systems (option D) to clearly define the target scope and avoid legal issues. Option A (list of specific tools) is not necessarily required in the scope; tools can be agreed upon but are not essential. Option C (vulnerability scanning schedule) is a separate activity and not part of penetration test scope. Option E (detailed client-side exploitation plan) is too specific and not a required element of the overall scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
List of specific exploitation tools to be used.
Why it's wrong here
Specifying a list of exact exploitation tools within a penetration test scope document is generally inappropriate. Such a mandate can unduly restrict the penetration tester's methodology and professional judgment, potentially hindering their ability to adapt to discovered vulnerabilities or leverage the most effective techniques. The scope should define what is to be tested and what objectives are to be achieved, not how the tester must perform their work, allowing them the flexibility to choose the best tools for the job.
- ✓
Time windows when testing is permitted (e.g., after business hours).
Why this is correct
Defining specific time windows during which penetration testing is permitted is a critical component of the Rules of Engagement (RoE). This ensures that testing activities, which can sometimes be disruptive or resource-intensive, occur during periods of low operational impact, such as after business hours or on weekends. Establishing these boundaries helps prevent service interruptions to critical business functions and minimizes potential negative effects on user experience or system availability.
- ✗
Schedule for automated vulnerability scanning of all external systems.
Why it's wrong here
A schedule for automated vulnerability scanning of all external systems is not typically included in a penetration test scope document because vulnerability scanning is a distinct security activity. While both aim to identify weaknesses, scanning is an automated process focused on enumeration and identification, whereas penetration testing involves manual exploitation to validate vulnerabilities and assess real-world impact. Their methodologies, objectives, and scheduling requirements are fundamentally different, necessitating separate planning.
- ✓
List of IP addresses and systems authorized for testing.
Why this is correct
Providing a precise list of IP addresses and systems explicitly authorized for testing is paramount for any penetration test. This detailed specification establishes clear boundaries for the assessment, preventing the testing team from inadvertently targeting critical production systems or assets that are out of scope. Such explicit authorization is crucial for legal compliance, ethical conduct, and ensuring that the organization grants permission only for the intended targets, thereby avoiding potential damage or legal repercussions.
- ✗
Detailed plan for exploiting client-side vulnerabilities.
Why it's wrong here
A detailed plan for exploiting client-side vulnerabilities is typically outside the scope of a standard network penetration test. Network penetration tests primarily focus on infrastructure, network devices, and server-side applications accessible over the network. Client-side attacks, such as those involving web browser exploits or social engineering to compromise end-user workstations, usually fall under specialized assessments like social engineering tests, web application penetration tests, or red team exercises, which have different objectives and methodologies.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.