nerdexam
CompTIA

PT0-002 · Question #403

Which of the following members of a client organization are most likely authorized to provide a signed authorization letter prior to the start date of a penetration test?

The correct answer is B. The executive management team and legal personnel. The executive management team and legal personnel are most likely authorized to provide a signed authorization letter for a penetration test, as they possess the authority to approve such a high-impact engagement and ensure legal compliance. This formal authorization is…

Planning and Scoping

Question

Which of the following members of a client organization are most likely authorized to provide a signed authorization letter prior to the start date of a penetration test?

Options

  • AThe IT department
  • BThe executive management team and legal personnel
  • COrganizational security personnel
  • DThe human resources team

How the community answered

(50 responses)
  • A
    2% (1)
  • B
    94% (47)
  • D
    4% (2)

Why each option

The executive management team and legal personnel are most likely authorized to provide a signed authorization letter for a penetration test, as they possess the authority to approve such a high-impact engagement and ensure legal compliance. This formal authorization is critical for validating the legitimacy and scope of the test.

AThe IT department

The IT department typically manages systems but often lacks the ultimate authority for formal approval of a penetration test due to its potential impact and legal implications.

BThe executive management team and legal personnelCorrect

A penetration test involves simulating real-world attacks, potentially impacting business operations and data, and carries significant legal implications. Therefore, executive management (e.g., CEO, CIO, CISO) has the organizational authority to approve such an intrusive activity, while legal personnel ensure that the scope and terms comply with laws and internal policies, making their combined authorization crucial and legally binding.

COrganizational security personnel

Organizational security personnel define security requirements and may manage the penetration test, but they generally require executive-level authorization to proceed with a formal, potentially disruptive test.

DThe human resources team

The human resources team is responsible for personnel matters and has no direct authority or responsibility over authorizing technical security assessments like penetration tests.

Concept tested: Penetration testing authorization and scope

Topics

#Pre-engagement#Authorization letter#Legal authorization#Stakeholder roles

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice