PT0-002 · Question #208
Which of the following documents must be signed between the penetration tester and the client to govern how any provided information is managed before, during, and after the engagement?
The correct answer is B. NDA. The Non-Disclosure Agreement (NDA) is the document governing the management of confidential information between the penetration tester and the client before, during, and after an engagement.
Question
Which of the following documents must be signed between the penetration tester and the client to govern how any provided information is managed before, during, and after the engagement?
Options
- AMSA
- BNDA
- CSOW
- DROE
How the community answered
(31 responses)- A3% (1)
- B94% (29)
- D3% (1)
Why each option
The Non-Disclosure Agreement (NDA) is the document governing the management of confidential information between the penetration tester and the client before, during, and after an engagement.
A Master Service Agreement (MSA) is a broad contract for overall terms of service, but it typically doesn't detail specific confidentiality requirements as thoroughly as an NDA.
A Non-Disclosure Agreement (NDA) is a legally binding contract specifically designed to protect confidential information. It obligates the penetration tester to keep any sensitive data obtained from the client, or findings discovered during the assessment, confidential and outlines how that information must be managed and protected throughout and beyond the engagement.
A Statement of Work (SOW) defines the specific tasks, deliverables, and timelines of the penetration testing project itself, not primarily the confidentiality of information.
Rules of Engagement (ROE) outline the scope, authorized methods, and boundaries of the penetration test, rather than governing how confidential information is managed.
Concept tested: Legal documents in penetration testing, confidentiality
Source: null
Topics
Community Discussion
No community discussion yet for this question.