ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 399 - PT0-002 discussion

Report
Export

Which of the following documents should be consulted if a client has an issue accepting a penetration test report that was provided?

A.
Rules of engagement
Answers
A.
Rules of engagement
B.
Signed authorization letter
Answers
B.
Signed authorization letter
C.
Statement of work
Answers
C.
Statement of work
D.
Non-disclosure agreement
Answers
D.
Non-disclosure agreement
Suggested answer: A

Explanation:

The Rules of Engagement (RoE) document is crucial when there's a dispute or issue with accepting a penetration test report. The RoE outlines the scope, methods, timing, legal considerations, and objectives of a penetration test. It serves as a guideline for both the client and the testing team on what is expected and permissible during the assessment. If there are issues with the report, referring back to the agreed-upon RoE can clarify whether the test was conducted within the agreed parameters and help resolve any disputes.

The signed authorization letter, statement of work, and non-disclosure agreement are also important documents but are more related to the permission, scope of work, and confidentiality aspects of the engagement, respectively, rather than the specifics of how the test was to be conducted, which is what the RoE covers.

asked 02/10/2024
Kris Dayananda
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first