
EC-CouncilCertified Penetration Testing Professional
Domain 1Objective 2
Penetration Testing Scoping and Engagement CPENT Practice Questions (Page 5)
Part of the Penetration Testing Foundations and Scoping domain, which makes up ~15% of our current practice bank.
39questions here
8free pages
5concepts
Questions 21–25
- 21
Which stakeholder group is most likely to need a non-technical summary of the engagement scope?
Select an answer first - 22
Which item is a typical deliverable of a penetration testing engagement?
Select an answer first - 23
A penetration tester is scoping an engagement for a client that hosts a public web application and an internal HR system. The client wants the tester to attempt to breach the internal HR system but explicitly forbids any testing of the third-party payment processor that the web application integrates with. Which action best aligns with the scope definition?
Select an answer first - 24
A penetration tester is scoping an engagement for a client that has a multi-tenant cloud environment. The client wants to test their application, but the application shares infrastructure with other tenants. The client has provided the tester with access to their own virtual network and resources. What is the most important consideration for the scope?
Select an answer first - 25
A penetration tester is communicating the scope of an engagement to a client's IT team. The client's IT team is concerned that the testing might affect a legacy system that is critical to operations. The tester has already defined the scope to exclude that system. What is the best way to communicate this to the IT team?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.