nerdexam
CompTIA

PT0-001 · Question #22

A client has requested an external network penetration test for compliance purposes. During discussion between the client and the penetration tester, the client expresses unwillingness to add the…

The correct answer is D. Testing should focus on the discovery of possible security issues across all in-scope systems, not. Whitelisting the penetration tester's source IPs ensures the IPS does not block test traffic, allowing the assessment to cover all in-scope systems rather than simply measuring IPS filtering effectiveness.

Engagement management

Question

A client has requested an external network penetration test for compliance purposes. During discussion between the client and the penetration tester, the client expresses unwillingness to add the penetration tester's source IP addresses to the client's IPS whitelist for the duration of the test. Which of the following is the BEST argument as to why the penetration tester's source IP addresses should be whitelisted?

Options

  • AWhitelisting prevents a possible inadvertent DoS attack against the IPS and supporting log-
  • BPenetration testing of third-party IPS systems often requires additional documentation and
  • CIPS whitelisting rules require frequent updates to stay current, constantly developing
  • DTesting should focus on the discovery of possible security issues across all in-scope systems, not

How the community answered

(32 responses)
  • B
    6% (2)
  • C
    3% (1)
  • D
    91% (29)

Why each option

Whitelisting the penetration tester's source IPs ensures the IPS does not block test traffic, allowing the assessment to cover all in-scope systems rather than simply measuring IPS filtering effectiveness.

AWhitelisting prevents a possible inadvertent DoS attack against the IPS and supporting log-

An IPS is a passive inspection device and is not at meaningful risk of a DoS from log volume generated by pen test traffic, making this a technically unsound justification for whitelisting.

BPenetration testing of third-party IPS systems often requires additional documentation and

Third-party IPS vendor documentation requirements are a procurement and contractual concern, not a technical reason for source IP whitelisting during an engagement.

CIPS whitelisting rules require frequent updates to stay current, constantly developing

The maintenance cadence of IPS signature rules is unrelated to the operational need to whitelist a tester's source IPs for the duration of an assessment.

DTesting should focus on the discovery of possible security issues across all in-scope systems, notCorrect

The purpose of a penetration test is to discover vulnerabilities across all in-scope systems; if the IPS blocks the tester's traffic without whitelisting, the engagement only evaluates IPS blocking capability and misses weaknesses in the systems behind it. Whitelisting ensures full test coverage so the client receives actionable findings on their actual attack surface, not just a report on IPS block rates.

Concept tested: Penetration test scope and IPS source IP whitelisting rationale

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#IPS whitelisting#engagement scope#compliance testing#penetration test planning

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice