ExamGecko
Question list
Search
Search

Related questions











Question 969 - CISA discussion

Report
Export

Which of the following should be done FIRST when planning to conduct internal and external penetration testing for a client?

A.
Establish the timing of testing.
Answers
A.
Establish the timing of testing.
B.
Identify milestones.
Answers
B.
Identify milestones.
C.
Determine the test reporting
Answers
C.
Determine the test reporting
D.
Establish the rules of engagement.
Answers
D.
Establish the rules of engagement.
Suggested answer: D

Explanation:

The rules of engagement define the scope, objectives, methodology, deliverables, and limitations of the penetration testing. They also specify the legal and ethical boundaries, communication channels, and escalation procedures. Establishing the rules of engagement is the first step when planning to conduct penetration testing for a client, as it ensures that both parties agree on the expectations and outcomes of the testing.The other options are important steps, but they should be done after the rules of engagement are established.Reference:CISA Review Manual (Digital Version)1, page 381.

asked 18/09/2024
Sorin Craia
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first