CAS-005 · Question #457
A company recently migrated its critical web application to a cloud provider's environment. As part of the company's risk management program, the company intends to conduct an external penetration…
The correct answer is B. Obtain agreement between the company and the cloud provider to conduct penetration testing. Most cloud providers require explicit authorization before any penetration testing is performed against their infrastructure. Even though the application is yours, the underlying network, hypervisor, and shared services belong to the CSP. Securing written approval (or verifying…
Question
A company recently migrated its critical web application to a cloud provider’s environment. As part of the company’s risk management program, the company intends to conduct an external penetration test. According to the scope of work and the rules of engagement, the penetration tester will validate the web application’s security and check for opportunities to expose sensitive company information in the newly migrated cloud environment. Which of the following should be the first consideration prior to engaging in the test?
Options
- APrepare a redundant server to ensure the critical web application's availability during the test.
- BObtain agreement between the company and the cloud provider to conduct penetration testing.
- CEnsure the latest patches and signatures are deployed on the web server.
- DCreate an NDA between the external penetration tester and the company.
How the community answered
(41 responses)- A10% (4)
- B68% (28)
- C5% (2)
- D17% (7)
Explanation
Most cloud providers require explicit authorization before any penetration testing is performed against their infrastructure. Even though the application is yours, the underlying network, hypervisor, and shared services belong to the CSP. Securing written approval (or verifying that the provider’s policy allows the planned tests without advance notice) ensures you won’t violate the provider’s terms of service or trigger automated abuse defenses that could disrupt service.
Community Discussion
No community discussion yet for this question.