PT0-002 · Question #403
Which of the following members of a client organization are most likely authorized to provide a signed authorization letter prior to the start date of a penetration test?
The correct answer is B. The executive management team and legal personnel. The executive management team and legal personnel are most likely authorized to provide a signed authorization letter for a penetration test, as they possess the authority to approve such a high-impact engagement and ensure legal compliance. This formal authorization is…
Question
Which of the following members of a client organization are most likely authorized to provide a signed authorization letter prior to the start date of a penetration test?
Options
- AThe IT department
- BThe executive management team and legal personnel
- COrganizational security personnel
- DThe human resources team
How the community answered
(50 responses)- A2% (1)
- B94% (47)
- D4% (2)
Why each option
The executive management team and legal personnel are most likely authorized to provide a signed authorization letter for a penetration test, as they possess the authority to approve such a high-impact engagement and ensure legal compliance. This formal authorization is critical for validating the legitimacy and scope of the test.
The IT department typically manages systems but often lacks the ultimate authority for formal approval of a penetration test due to its potential impact and legal implications.
A penetration test involves simulating real-world attacks, potentially impacting business operations and data, and carries significant legal implications. Therefore, executive management (e.g., CEO, CIO, CISO) has the organizational authority to approve such an intrusive activity, while legal personnel ensure that the scope and terms comply with laws and internal policies, making their combined authorization crucial and legally binding.
Organizational security personnel define security requirements and may manage the penetration test, but they generally require executive-level authorization to proceed with a formal, potentially disruptive test.
The human resources team is responsible for personnel matters and has no direct authority or responsibility over authorizing technical security assessments like penetration tests.
Concept tested: Penetration testing authorization and scope
Topics
Community Discussion
No community discussion yet for this question.