nerdexam
CompTIA

PT0-001 · Question #122

A company planned for and secured the budget to hire a consultant to perform a web application penetration test. Upon discovered vulnerabilities, the company asked the consultant to perform the…

The correct answer is A. Scope creep. A scope creep, or the addition of more items and targets to the scope of the assessment, is a constant menace for penetration testing. During the scoping phase, a tester is unlikely to know all of the details of what may be uncovered, and during the assessment itself, a tester…

Engagement management

Question

A company planned for and secured the budget to hire a consultant to perform a web application penetration test. Upon discovered vulnerabilities, the company asked the consultant to perform the following tasks:

  • Code review
  • Updates to firewall setting

Options

  • AScope creep
  • BPost-mortem review
  • CRisk acceptance
  • DThreat prevention

How the community answered

(18 responses)
  • A
    89% (16)
  • B
    6% (1)
  • C
    6% (1)

Explanation

A scope creep, or the addition of more items and targets to the scope of the assessment, is a constant menace for penetration testing. During the scoping phase, a tester is unlikely to know all of the details of what may be uncovered, and during the assessment itself, a tester may encounter unexpected new targets. Scope creep refers to how a project’s requirements tend to increase over a project life cycle.

Topics

#scope creep#engagement scope#rules of engagement#web application testing

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice