
EC-CouncilCertified Penetration Testing Professional
Domain 1Objective 2
Penetration Testing Scoping and Engagement CPENT Practice Questions (Page 4)
Part of the Penetration Testing Foundations and Scoping domain, which makes up ~15% of our current practice bank.
39questions here
8free pages
5concepts
Questions 16–20
- 16
A penetration tester is completing a grey-box engagement for a client. The client has provided the tester with a list of IP addresses and credentials for the target systems. During the test, the tester discovers a critical vulnerability that could allow an attacker to gain administrative access. The client has requested that the final report include a proof of concept (PoC) for each vulnerability. What is the most important consideration when including the PoC?
Select an answer first - 17
A penetration tester is working with a client that has multiple business units. One business unit wants to test a critical application, but another business unit is concerned about the test affecting their shared infrastructure. The tester must communicate the scope to all stakeholders. What is the best approach?
Select an answer first - 18
A penetration tester is scoping an engagement for a client that has a complex network with multiple subsidiaries. The client wants to test a specific application that is hosted in a cloud environment, but the application's data is stored in a different region than the client's headquarters. The client has provided the tester with credentials to the cloud environment but has not specified the exact boundaries of the test. The tester must ensure the test does not accidentally access other subsidiaries' data. What is the most critical action the tester should take?
Select an answer first - 19
A client wants to test the effectiveness of their security monitoring and incident response processes. They want the test to be as realistic as possible, but they are concerned about the risk of a real attacker causing damage. Which engagement type is most appropriate?
Select an answer first - 20
A penetration tester is preparing rules of engagement for a client. The client requires that all testing be performed between 2 AM and 6 AM to avoid impacting production. The tester plans to use active scanning tools that may generate alerts. Which component must be explicitly documented in the rules of engagement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.