nerdexam
GIAC

GPEN · Question #404

You have been contracted to map me network and try to compromise the servers for a client. Which of the following would be an example of scope creep' with respect to this penetration testing project?

The correct answer is B. Compromising a server then escalating privileges. Scope creep occurs when a tester performs activities beyond the explicitly authorized boundaries; escalating privileges after compromising a server exceeds the contracted scope of network mapping and server compromise.

Penetration Testing Foundations & Reconnaissance

Question

You have been contracted to map me network and try to compromise the servers for a client. Which of the following would be an example of scope creep' with respect to this penetration testing project?

Options

  • ADisclosing information forbidden in the NDA
  • BCompromising a server then escalating privileges
  • CBeing asked to compromise workstations
  • DScanning network systems slowly so you are not detected

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    74% (32)
  • C
    7% (3)
  • D
    16% (7)

Why each option

Scope creep occurs when a tester performs activities beyond the explicitly authorized boundaries; escalating privileges after compromising a server exceeds the contracted scope of network mapping and server compromise.

ADisclosing information forbidden in the NDA

Disclosing NDA-forbidden information is a legal and contractual breach, not scope creep - it violates the non-disclosure agreement terms rather than expanding the technical boundaries of the engagement.

BCompromising a server then escalating privilegesCorrect

The engagement was contracted specifically to map the network and attempt to compromise servers. Escalating privileges is a post-exploitation activity that was not included in the original written authorization, making it an unauthorized expansion of the engagement. Any activity beyond initial compromise - including privilege escalation, lateral movement, or data exfiltration - requires explicit written authorization to avoid legal liability and ethical violations.

CBeing asked to compromise workstations

Being asked by the client to compromise workstations represents a client-initiated scope change request, which is a formal expansion requiring a new authorization - not unauthorized scope creep by the tester.

DScanning network systems slowly so you are not detected

Scanning slowly to avoid detection is a recognized and acceptable technique within network mapping engagements and does not exceed the agreed scope.

Concept tested: Penetration testing scope creep and authorized engagement boundaries

Source: https://www.pentest-standard.org/index.php/Pre-engagement

Topics

#scope creep#rules of engagement#engagement boundaries#pentest ethics

Community Discussion

No community discussion yet for this question.

Full GPEN Practice