Courseiva
Security Assessment and TestingeasyMultiple ChoiceObjective-mapped

CISSP Security Assessment and Testing Practice Question

Which of the following is a key element of the rules of engagement for a penetration test?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Emergency stop criteria

Rules of engagement must include written authorization and define the scope, including systems to be tested and emergency stop criteria.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Emergency stop criteria

    Why this is correct

    Rules of Engagement (RoE) are critical for defining the scope, boundaries, and acceptable methods of a penetration test or security assessment. Emergency stop criteria are a fundamental element within the RoE, explicitly outlining specific conditions or thresholds that, if met, necessitate an immediate cessation of testing activities. These criteria are crucial for preventing unintended service disruptions, data corruption, or irreversible damage to the target systems, ensuring the integrity and availability of the client's environment are maintained even during aggressive testing. They often include triggers like critical system crashes, excessive network latency, or detection of unauthorized access to non-target systems.

  • The tester's compensation

    Why it's wrong here

    The tester's compensation, including payment terms, rates, and invoicing schedules, is a contractual matter typically detailed within the master service agreement (MSA) or a statement of work (SOW) between the client and the testing firm. While essential for the business relationship, these financial details do not directly govern the technical conduct, scope, or operational boundaries of the security assessment itself. Rules of Engagement focus strictly on the technical parameters and ethical guidelines for the actual testing activities, not the financial arrangements for the service.

  • The tester's background check

    Why it's wrong here

    A tester's background check is a pre-engagement due diligence activity performed by the hiring organization or the client to verify the tester's trustworthiness and suitability for handling sensitive information and systems. This process typically occurs long before the actual security assessment begins and is part of personnel security, not the operational framework for the test itself. Rules of Engagement, conversely, define the specific technical parameters, authorized actions, and limitations that govern the execution of the penetration test or vulnerability assessment.

  • The number of vulnerabilities to find

    Why it's wrong here

    Specifying a predetermined "number of vulnerabilities to find" is fundamentally antithetical to the objective and nature of a professional security assessment. The goal of a penetration test or vulnerability assessment is to identify all exploitable weaknesses within the defined scope, not to meet an arbitrary quota. Rules of Engagement define the scope, methodology, and constraints of the test, but they do not set performance metrics based on discovery quantity, as this could incentivize superficial findings or misrepresent the true security posture.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.