nerdexam
CompTIA

PT0-002 · Question #122

A company planned for and secured the budget to hire a consultant to perform a web application penetration test. Upon discovered vulnerabilities, the company asked the consultant to perform the…

The correct answer is A. Scope creep. A scope creep, or the addition of more items and targets to the scope of the assessment, is a constant menace for penetration testing. During the scoping phase, a tester is unlikely to know all of the details of what may be uncovered, and during the assessment itself, a tester…

Engagement management

Question

A company planned for and secured the budget to hire a consultant to perform a web application penetration test. Upon discovered vulnerabilities, the company asked the consultant to perform the following tasks:

  • Code review
  • Updates to firewall setting

Options

  • AScope creep
  • BPost-mortem review
  • CRisk acceptance
  • DThreat prevention

How the community answered

(39 responses)
  • A
    85% (33)
  • B
    3% (1)
  • C
    3% (1)
  • D
    10% (4)

Explanation

A scope creep, or the addition of more items and targets to the scope of the assessment, is a constant menace for penetration testing. During the scoping phase, a tester is unlikely to know all of the details of what may be uncovered, and during the assessment itself, a tester may encounter unexpected new targets. Scope creep refers to how a project’s requirements tend to increase over a project life cycle.

Topics

#Scope creep#Penetration testing management#Project management#Engagement lifecycle

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice