PT0-002 · Question #36
A penetration tester is working on a scoping document with a new client. The methodology the client uses includes the following: Pre-engagement interaction (scoping and ROE) Intelligence gathering…
The correct answer is B. PTES technical guidelines. The methodology described - Pre-engagement interaction, Intelligence gathering, Threat modeling, Vulnerability analysis, Exploitation and post-exploitation, Reporting - maps exactly to the Penetration Testing Execution Standard (PTES). PTES is a community-driven standard that…
Question
A penetration tester is working on a scoping document with a new client. The methodology the client uses includes the following:
Pre-engagement interaction (scoping and ROE) Intelligence gathering (reconnaissance) Threat modeling Vulnerability analysis Exploitation and post exploitation Reporting Which of the following methodologies does the client use?
Options
- AOWASP Web Security Testing Guide
- BPTES technical guidelines
- CNIST SP 800-115
- DOSSTMM
How the community answered
(48 responses)- A6% (3)
- B88% (42)
- C4% (2)
- D2% (1)
Explanation
The methodology described - Pre-engagement interaction, Intelligence gathering, Threat modeling, Vulnerability analysis, Exploitation and post-exploitation, Reporting - maps exactly to the Penetration Testing Execution Standard (PTES). PTES is a community-driven standard that defines a full penetration testing lifecycle. OWASP WSTG (A) focuses specifically on web application testing. NIST SP 800-115 (C) is a technical guide for information security testing but uses different phase names. OSSTMM (D) is the Open Source Security Testing Methodology Manual, which focuses on operational security metrics and uses a different structure (e.g., RAV scoring). The pre-engagement/ROE + threat modeling combination is a distinctive PTES identifier.
Topics
Community Discussion
No community discussion yet for this question.