nerdexam
EC-Council

312-50V9 · Question #483

As a Certified Ethical Hacker, you were contracted by a private firm to conduct an external security assessment through penetration testing. What document describes the specifics of the testing, the…

The correct answer is A. Terms of Engagement. The Terms of Engagement is the formal contract that authorizes a penetration test, defines permissible actions, and establishes legal protections for both the tester and the client.

Introduction to Ethical Hacking

Question

As a Certified Ethical Hacker, you were contracted by a private firm to conduct an external security assessment through penetration testing. What document describes the specifics of the testing, the associated violations, and essentially protects both the organization's interest and your liabilities as a tester?

Options

  • ATerms of Engagement
  • BProject Scope
  • CNon-Disclosure Agreement
  • DService Level Agreement

How the community answered

(39 responses)
  • A
    95% (37)
  • B
    3% (1)
  • D
    3% (1)

Why each option

The Terms of Engagement is the formal contract that authorizes a penetration test, defines permissible actions, and establishes legal protections for both the tester and the client.

ATerms of EngagementCorrect

The Terms of Engagement document specifies exactly what systems may be tested, which actions are authorized versus prohibited, the timeline, and the legal liability boundaries for both parties. It serves as the written authorization that differentiates ethical hacking from criminal activity. Without this document, a tester has no legal protection if the client later disputes the scope or claims damages.

BProject Scope

Project Scope only defines which systems or assets are included in the assessment and does not address legal violations, permitted testing methods, or mutual liability protections.

CNon-Disclosure Agreement

A Non-Disclosure Agreement governs the confidentiality of information shared between parties but does not authorize testing activities or define liabilities for the tester.

DService Level Agreement

A Service Level Agreement defines performance and uptime standards for ongoing services and has no relevance to penetration testing authorization or liability.

Concept tested: Penetration testing legal authorization and engagement documentation

Source: http://www.pentest-standard.org/index.php/Pre-engagement

Topics

#terms of engagement#penetration testing#legal agreements#project scope

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice