CISM · Question #124
When engaging an external party to perform a penetration test, it is MOST important to:
The correct answer is C. define the project scope. When engaging an external penetration testing firm, defining the project scope is the most critical step to ensure the test is effective, authorized, and avoids unintended consequences.
Question
When engaging an external party to perform a penetration test, it is MOST important to:
Options
- Aprovide an updated asset inventory.
- Bnotify employees of the testing.
- Cdefine the project scope.
- Dprovide network documentation.
How the community answered
(56 responses)- A14% (8)
- B4% (2)
- C73% (41)
- D9% (5)
Why each option
When engaging an external penetration testing firm, defining the project scope is the most critical step to ensure the test is effective, authorized, and avoids unintended consequences.
While an asset inventory is helpful, the scope dictates *which* assets from the inventory are relevant for the test, making scope definition primary.
Notifying employees is a consideration (especially for social engineering), but it's secondary to defining what the testers are allowed to do. In some tests, employees are intentionally *not* notified.
Clearly defining the project scope, including specific targets, permitted methodologies, timing, and out-of-scope assets, is paramount to ensure the penetration test focuses on the intended areas, remains within legal and ethical boundaries, and yields relevant results. A well-defined scope prevents scope creep, unauthorized activities, and potential disruption to critical systems.
Network documentation can be provided as part of the test (e.g., white-box testing), but the decision to provide it and the extent to which it's used is determined by the overall scope.
Concept tested: Penetration test planning
Topics
Community Discussion
No community discussion yet for this question.