PT0-002 · Question #122
A company planned for and secured the budget to hire a consultant to perform a web application penetration test. Upon discovered vulnerabilities, the company asked the consultant to perform the…
The correct answer is A. Scope creep. A scope creep, or the addition of more items and targets to the scope of the assessment, is a constant menace for penetration testing. During the scoping phase, a tester is unlikely to know all of the details of what may be uncovered, and during the assessment itself, a tester…
Question
A company planned for and secured the budget to hire a consultant to perform a web application penetration test. Upon discovered vulnerabilities, the company asked the consultant to perform the following tasks:
- Code review
- Updates to firewall setting
Options
- AScope creep
- BPost-mortem review
- CRisk acceptance
- DThreat prevention
How the community answered
(39 responses)- A85% (33)
- B3% (1)
- C3% (1)
- D10% (4)
Explanation
A scope creep, or the addition of more items and targets to the scope of the assessment, is a constant menace for penetration testing. During the scoping phase, a tester is unlikely to know all of the details of what may be uncovered, and during the assessment itself, a tester may encounter unexpected new targets. Scope creep refers to how a project’s requirements tend to increase over a project life cycle.
Topics
Community Discussion
No community discussion yet for this question.