CompTIA PenTest+: Scoping an Engagement
Which of the following would be considered examples of hostile threat actors?
Corporate competitor Disgruntled ex-employee Hacktivist Cyber miner
Which one of the following would NOT be a reason to perform compliance testing?
ISACA
In order to have clearly defined penetration objectives based on regulations, methodologies are commonly based on the industry-accepted penetration testing approaches. Which one of the following would NOT apply?
MARS-E
What is one of the quickest ways for a penetration testing firm to lose customers and potentially go out of business?
Regularly allowing for scope creep
What type of risk treatment often involves cyber insurance?
Risk transfer
What type of test is best characterized by both the tester and security teams working together and appraising each other of their movements?
Targeted test
Which of the following statements is NOT true concerning the pre-engagement scoping meeting?
This stage is much too soon for signing NDAs
A penetration tester has wide-ranging knowledge and visibility into the target system or application. Which type of test is this?
White box