ExamGecko
Question list
Search
Search

Related questions

Question 64 - CISA discussion

Report
Export

Which of the following should be done FIRST when planning a penetration test?

A.
Execute nondisclosure agreements (NDAs).
Answers
A.
Execute nondisclosure agreements (NDAs).
B.
Determine reporting requirements for vulnerabilities.
Answers
B.
Determine reporting requirements for vulnerabilities.
C.
Define the testing scope.
Answers
C.
Define the testing scope.
D.
Obtain management consent for the testing.
Answers
D.
Obtain management consent for the testing.
Suggested answer: D

Explanation:

The first step when planning a penetration test is to obtain management consent for the testing. This is because a penetration test involves simulating a cyberattack against the organization's systems and networks, which may have legal, ethical, and operational implications. Without proper authorization from management, a penetration test may violate laws, policies, contracts, or service level agreements. Management consent also helps define the objectives, scope, and boundaries of the test, as well as the roles and responsibilities of the testers and the stakeholders. Obtaining management consent for the testing also demonstrates due care and due diligence on the part of the testers and the organization.

Executing nondisclosure agreements (NDAs), determining reporting requirements for vulnerabilities, and defining the testing scope are important steps when planning a penetration test, but they are not the first step. These steps should be done after obtaining management consent for the testing, as they depend on the approval and involvement of management and other parties.

asked 18/09/2024
Rajesh Gurav
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first