CISSP Security Assessment and Testing Practice Question
Which of the following is a key component of the rules of engagement for a penetration test?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Emergency stop criteria
Rules of engagement must include written authorization, scope definition, and emergency stop criteria to ensure legal and safe testing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exploitation techniques to use
Why it's wrong here
While specific exploitation techniques might be outlined within a detailed Rules of Engagement (RoE) document to clarify permissible actions, they are not considered a key component in the same vein as scope, authorization, or emergency procedures. The RoE primarily establishes the legal and ethical boundaries, objectives, and communication protocols for an engagement, rather than serving as a tactical playbook for specific attack methods. Defining the types of techniques allowed (e.g., social engineering, network scanning) is more aligned with scope than the granular details of how to execute them.
- ✓
Emergency stop criteria
Why this is correct
Emergency stop criteria are a critical component of the Rules of Engagement (RoE) because they explicitly define the conditions under which an engagement must be immediately halted to prevent unintended harm, legal issues, or excessive risk. These criteria ensure that testing can be safely terminated if unexpected system instability, unauthorized access to sensitive data, or other critical incidents occur, thereby protecting the target environment and the testing team. Establishing these clear boundaries is fundamental to responsible and controlled security assessments.
- ✗
CVSS score of vulnerabilities
Why it's wrong here
The Common Vulnerability Scoring System (CVSS) score of vulnerabilities is a metric used to quantify the severity of discovered weaknesses, typically generated after a vulnerability assessment or penetration test is conducted. It is a crucial element of the final reporting phase, informing remediation priorities, but it is not a component of the Rules of Engagement. RoE documents are established before testing begins to define the scope, authorization, and operational parameters, not to report on findings.
- ✗
Number of vulnerabilities found
Why it's wrong here
The number of vulnerabilities found is an outcome or metric derived from the execution of a security assessment, serving as a quantitative measure of the findings. This figure is a result of the testing process and is typically included in the final report to stakeholders. It cannot be a component of the Rules of Engagement, which are pre-defined agreements and guidelines established before the assessment commences to govern its conduct, scope, and authorized activities.
Go deeper
Related to this question
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.