PT0-002 · Question #229
A customer adds a requirement to the scope of a penetration test that states activities can only occur during normal business hours. Which of the following BEST describes why this would be necessary?
The correct answer is D. To ensure someone is available if something goes wrong. A customer's requirement to conduct penetration testing activities only during normal business hours is primarily to ensure that technical staff are available to respond promptly if any issues or disruptions arise from the testing.
Question
A customer adds a requirement to the scope of a penetration test that states activities can only occur during normal business hours. Which of the following BEST describes why this would be necessary?
Options
- ATo meet PCI DSS testing requirements
- BFor testing of the customer's SLA with the ISP
- CBecause of concerns regarding bandwidth limitations
- DTo ensure someone is available if something goes wrong
How the community answered
(37 responses)- A5% (2)
- C3% (1)
- D92% (34)
Why each option
A customer's requirement to conduct penetration testing activities only during normal business hours is primarily to ensure that technical staff are available to respond promptly if any issues or disruptions arise from the testing.
While PCI DSS requires penetration testing, it does not specifically mandate that these activities must occur exclusively during normal business hours.
Testing the customer's SLA with their ISP involves different metrics and testing methodologies, and scheduling penetration tests during business hours is not directly related to this.
Limiting activities to business hours often increases the risk of impacting operational bandwidth during peak usage times, which contradicts the goal of avoiding performance issues due to bandwidth limitations.
Restricting penetration testing activities to normal business hours ensures that the client's IT staff and other relevant personnel are available and on-site to immediately address any unforeseen issues, system disruptions, or outages that might occur during the test.
Concept tested: Penetration testing scope and risk management
Source: https://www.nist.gov/document/nist-sp-800-115-technical-guide-information-security-testing-and-assessment
Topics
Community Discussion
No community discussion yet for this question.