nerdexam
CompTIA

PT0-002 · Question #530

Which of the following documents best ensures an external consulting firm that is hired to perform a penetration test understands and complies with the customer's security policies and procedures?

The correct answer is A. ROE. Rules of Engagement (ROE) is the document that formally defines the scope, boundaries, permitted techniques, timing, and rules the penetration tester must follow during the engagement - including compliance with the client's security policies and procedures. It acts as the operat

Engagement management

Question

Which of the following documents best ensures an external consulting firm that is hired to perform a penetration test understands and complies with the customer's security policies and procedures?

Options

  • AROE
  • BMOU
  • CSLA
  • DNDA

How the community answered

(30 responses)
  • A
    93% (28)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Rules of Engagement (ROE) is the document that formally defines the scope, boundaries, permitted techniques, timing, and rules the penetration tester must follow during the engagement - including compliance with the client's security policies and procedures. It acts as the operational contract that governs tester behavior. An MOU (B) is a memorandum of understanding that outlines a general cooperative relationship but is not specific enough for security policy compliance. An SLA (C) defines service quality expectations, not security rules. An NDA (D) is a confidentiality agreement that protects sensitive information shared between parties, but does not govern how the tester must behave or comply with security policies during the test.

Topics

#Rules of Engagement#Penetration Testing#Compliance#Security Policies

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice