GPEN · Question #404
You have been contracted to map me network and try to compromise the servers for a client. Which of the following would be an example of scope creep' with respect to this penetration testing project?
The correct answer is B. Compromising a server then escalating privileges. Scope creep occurs when a tester performs activities beyond the explicitly authorized boundaries; escalating privileges after compromising a server exceeds the contracted scope of network mapping and server compromise.
Question
You have been contracted to map me network and try to compromise the servers for a client. Which of the following would be an example of scope creep' with respect to this penetration testing project?
Options
- ADisclosing information forbidden in the NDA
- BCompromising a server then escalating privileges
- CBeing asked to compromise workstations
- DScanning network systems slowly so you are not detected
How the community answered
(43 responses)- A2% (1)
- B74% (32)
- C7% (3)
- D16% (7)
Why each option
Scope creep occurs when a tester performs activities beyond the explicitly authorized boundaries; escalating privileges after compromising a server exceeds the contracted scope of network mapping and server compromise.
Disclosing NDA-forbidden information is a legal and contractual breach, not scope creep - it violates the non-disclosure agreement terms rather than expanding the technical boundaries of the engagement.
The engagement was contracted specifically to map the network and attempt to compromise servers. Escalating privileges is a post-exploitation activity that was not included in the original written authorization, making it an unauthorized expansion of the engagement. Any activity beyond initial compromise - including privilege escalation, lateral movement, or data exfiltration - requires explicit written authorization to avoid legal liability and ethical violations.
Being asked by the client to compromise workstations represents a client-initiated scope change request, which is a formal expansion requiring a new authorization - not unauthorized scope creep by the tester.
Scanning slowly to avoid detection is a recognized and acceptable technique within network mapping engagements and does not exceed the agreed scope.
Concept tested: Penetration testing scope creep and authorized engagement boundaries
Source: https://www.pentest-standard.org/index.php/Pre-engagement
Topics
Community Discussion
No community discussion yet for this question.