ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 419 - PT0-002 discussion

Report
Export

A penetration tester is hired to test a client's systems. The client's systems are hosted by the client at its headquarters. The production environment is hosted by a private cloud-hosting company. Which of the following would be the most important for the penetration tester to determine before beginning the test?

A.
Third-party asset restrictions
Answers
A.
Third-party asset restrictions
B.
Disallowed tests
Answers
B.
Disallowed tests
C.
Physical locations of the infrastructure
Answers
C.
Physical locations of the infrastructure
D.
Time-of-day restrictions
Answers
D.
Time-of-day restrictions
Suggested answer: A

Explanation:

Before beginning a penetration test, it is crucial to determine any restrictions related to third-party assets. This is particularly important when the client's systems are hosted by a third-party cloud provider. The penetration tester needs to know what limitations or restrictions are imposed by the third-party hosting company to avoid violating terms of service, causing unintended disruptions, or legal issues.

Understanding third-party asset restrictions ensures that the testing activities comply with legal and contractual obligations and avoid potential conflicts with the third-party provider.

Penetration testing considerations: OWASP Testing Guide

Experiences from various penetration testing engagements highlighting the importance of third-party restrictions: Anubis.

asked 02/10/2024
PATRICK ADUSEI
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first