ExamGecko
Question list
Search
Search

Related questions











Question 970 - CISA discussion

Report
Export

When planning an internal penetration test, which of the following is the MOST important step prior to finalizing the scope of testing?

A.
Ensuring the scope of penetration testing is restricted to the test environment
Answers
A.
Ensuring the scope of penetration testing is restricted to the test environment
B.
Obtaining management's consent to the testing scope in writing
Answers
B.
Obtaining management's consent to the testing scope in writing
C.
Notifying the IT security department regarding the testing scope
Answers
C.
Notifying the IT security department regarding the testing scope
D.
Agreeing on systems to be excluded from the testing scope with the IT department
Answers
D.
Agreeing on systems to be excluded from the testing scope with the IT department
Suggested answer: B

Explanation:

Obtaining management's consent to the testing scope in writing is the most important step prior to finalizing the scope of testing, as it ensures that the penetration testers have the authorization and approval to perform the testing activities. It also protects them from any legal liabilities or accusations of unauthorized access or damage. The other options are not as important as obtaining management's consent, and they may vary depending on the specific situation and agreement.For example, some systems may not be excluded from the testing scope, and some tests may not be restricted to the test environment.Reference:CISA Review Manual (Digital Version)1, page 381-382.

asked 18/09/2024
yusuf sivrikaya
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first