PT0-002 · Question #460
A penetration tester is hired to test a client's systems. The client's systems are hosted by the client at its headquarters. The production environment is hosted by a private cloud-hosting company…
The correct answer is A. Third-party asset restrictions. When a client's production environment is hosted by a third-party cloud provider, the penetration tester must determine what restrictions that third party imposes before any testing begins. Cloud providers (AWS, Azure, GCP, and private hosts alike) have their own Acceptable Use…
Question
A penetration tester is hired to test a client's systems. The client's systems are hosted by the client at its headquarters. The production environment is hosted by a private cloud-hosting company. Which of the following would be the most important for the penetration tester to determine before beginning the test?
Options
- AThird-party asset restrictions
- BDisallowed tests
- CPhysical locations of the infrastructure
- DTime-of-day restrictions
How the community answered
(41 responses)- A71% (29)
- B17% (7)
- C7% (3)
- D5% (2)
Explanation
When a client's production environment is hosted by a third-party cloud provider, the penetration tester must determine what restrictions that third party imposes before any testing begins. Cloud providers (AWS, Azure, GCP, and private hosts alike) have their own Acceptable Use Policies and may require advance notification, formal authorization, or prohibit certain testing types entirely on their infrastructure. Testing a cloud-hosted environment without the provider's knowledge or consent could violate legal agreements and expose both the tester and client to liability. Disallowed tests (B), physical locations (C), and time-of-day restrictions (D) are also scoping concerns, but third-party authorization is the most critical initial determination when shared infrastructure is involved.
Topics
Community Discussion
No community discussion yet for this question.