
EC-CouncilCertified Penetration Testing Professional
Domain 1Objective 2
Penetration Testing Scoping and Engagement CPENT Practice Questions (Page 7)
Part of the Penetration Testing Foundations and Scoping domain, which makes up ~15% of our current practice bank.
39questions here
8free pages
5concepts
Questions 31–35
- 31
A penetration tester is preparing a rules of engagement (RoE) document for a client. The client has specified that the test must not disrupt business operations during peak hours (9 AM to 5 PM) and that any testing that could cause a denial of service must be approved in advance. The tester plans to run a vulnerability scan that may cause high network load. What is the most appropriate action for the tester to take?
Select an answer first - 32
A penetration tester is planning a white-box engagement for a client. The client has provided the tester with access to the source code of their application and the network architecture. The tester is expected to identify vulnerabilities that might be missed in a black-box test. What is the primary advantage of this type of engagement?
Select an answer first - 33
What is the purpose of including remediation guidance in a penetration test report?
Select an answer first - 34
What is the primary purpose of communicating scope and engagement parameters to stakeholders before a penetration test begins?
Select an answer first - 35
A penetration tester is planning an engagement with a client. The client wants to ensure that the testing does not disrupt business operations. Which rules of engagement component is most important to address this concern?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.