PT0-001 · Question #122
A company planned for and secured the budget to hire a consultant to perform a web application penetration test. Upon discovered vulnerabilities, the company asked the consultant to perform the…
The correct answer is A. Scope creep. A scope creep, or the addition of more items and targets to the scope of the assessment, is a constant menace for penetration testing. During the scoping phase, a tester is unlikely to know all of the details of what may be uncovered, and during the assessment itself, a tester…
Question
A company planned for and secured the budget to hire a consultant to perform a web application penetration test. Upon discovered vulnerabilities, the company asked the consultant to perform the following tasks:
- Code review
- Updates to firewall setting
Options
- AScope creep
- BPost-mortem review
- CRisk acceptance
- DThreat prevention
How the community answered
(18 responses)- A89% (16)
- B6% (1)
- C6% (1)
Explanation
A scope creep, or the addition of more items and targets to the scope of the assessment, is a constant menace for penetration testing. During the scoping phase, a tester is unlikely to know all of the details of what may be uncovered, and during the assessment itself, a tester may encounter unexpected new targets. Scope creep refers to how a project’s requirements tend to increase over a project life cycle.
Topics
Community Discussion
No community discussion yet for this question.