nerdexam
(ISC)2

SSCP · Question #1325

Penetration testing involves three steps. At which step should an approve penetration test stop?

The correct answer is C. Network Penetration. An approved penetration test typically stops after successfully demonstrating network penetration and the exploitation of vulnerabilities, before causing actual damage or prolonged disruption.

Submitted by jian89· Apr 18, 2026Security Operations and Administration

Question

Penetration testing involves three steps. At which step should an approve penetration test stop?

Options

  • AWar Driving
  • BNetwork reconnaissance
  • CNetwork Penetration
  • DSystem Control
  • EDenial of system services
  • FNetwork scanning

How the community answered

(16 responses)
  • C
    69% (11)
  • D
    6% (1)
  • E
    6% (1)
  • F
    19% (3)

Why each option

An approved penetration test typically stops after successfully demonstrating network penetration and the exploitation of vulnerabilities, before causing actual damage or prolonged disruption.

AWar Driving

War Driving is a reconnaissance technique, and stopping there would not demonstrate successful penetration.

BNetwork reconnaissance

Network reconnaissance is the information gathering phase; stopping here would not demonstrate system vulnerabilities or penetration.

CNetwork PenetrationCorrect

An approved penetration test typically aims to demonstrate the successful exploitation of vulnerabilities and gain network penetration, stopping before causing actual harm or extended disruption to the target system.

DSystem Control

System control implies maintaining persistent access and potentially escalating privileges, which might exceed the scope of what is permitted in a typical approved penetration test's stopping point without explicit authorization.

EDenial of system services

Denial of system services would be a destructive action and is generally not an intended stopping point for an approved penetration test, which seeks to identify vulnerabilities without causing harm.

FNetwork scanning

Network scanning is a part of reconnaissance, and stopping there would not demonstrate successful penetration.

Concept tested: Penetration testing scope and limits

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing

Topics

#Penetration Testing#Pentest Phases#Security Assessment#Vulnerability Exploitation

Community Discussion

No community discussion yet for this question.

Full SSCP Practice