Unit 1: Planning and Scoping - Practice Quiz

INT245 — Penetration Testing 50 Questions
0 Correct 0 Wrong 50 Left
0/50

1 What is the primary objective of the Planning and Scoping phase in penetration testing?

A. To generate the final report for the stakeholders
B. To exploit known vulnerabilities in the target system
C. To define the rules of engagement, objectives, and boundaries of the test
D. To perform active scanning of the network perimeter

2 Which of the following best describes a Black Box penetration test?

A. The tester works alongside the internal security team to audit systems
B. The tester has full knowledge of the network infrastructure and source code
C. The tester has partial knowledge, such as user credentials but no network diagrams
D. The tester has zero prior knowledge of the target system, simulating an external attacker

3 In the context of the CIA Triad, penetration testing primarily seeks to ensure that security controls maintain:

A. Confidentiality, Integrity, and Availability
B. Control, Identity, and Authorization
C. Compliance, Inspection, and Auditing
D. Cost, Insurance, and Assessment

4 Which document is essential to obtain before starting any penetration testing activities to avoid legal liability?

A. Software License Agreement
B. Vulnerability Scan Report
C. Service Level Agreement (SLA)
D. Written Authorization (Get Out of Jail Free card)

5 In a White Box penetration test, which of the following is typically provided to the tester?

A. Physical access badges only
B. Network diagrams, source code, and IP addressing schemes
C. Only the company name
D. Only a URL to the public website

6 What distinguishes a Vulnerability Assessment from a Penetration Test?

A. There is no difference; the terms are interchangeable
B. Vulnerability assessments take longer to complete than penetration tests
C. Vulnerability assessments identify potential flaws; penetration tests attempt to exploit them to verify risk
D. Vulnerability assessments are manual; penetration tests are automated

7 Which regulatory standard applies specifically to organizations handling credit card information?

A. PCI-DSS
B. HIPAA
C. FERPA
D. GDPR

8 According to the PTES (Penetration Testing Execution Standard), which phase immediately follows Pre-engagement Interactions?

A. Post-Exploitation
B. Reporting
C. Intelligence Gathering
D. Exploitation

9 What is the purpose of the Rules of Engagement (RoE) document?

A. To define how the test will be conducted, constraints, timeline, and communication channels
B. To report the findings of the test after completion
C. To list the specific exploits that will be used
D. To detail the cost and payment terms of the contract

10 Which of the following implies a Gray Box testing approach?

A. The tester has no knowledge of the system
B. The tester acts as an authenticated user with limited knowledge of the backend
C. The tester audits the physical security of the building only
D. The tester has Administrator access to all servers

11 When defining Scope, what does the term "Out-of-Scope" refer to?

A. Tools that the tester is not allowed to use
B. Vulnerabilities that cannot be patched
C. Systems that have critical vulnerabilities
D. Assets or systems that must explicitly not be tested or touched

12 Which type of team is responsible for defending the network during a penetration test exercise?

A. Blue Team
B. Purple Team
C. White Team
D. Red Team

13 What is a Purple Team exercise?

A. A test conducted strictly by government auditors
B. A test focused solely on wireless networks
C. A collaborative effort where Red and Blue teams work together to improve detection and defense
D. A physical security assessment combined with social engineering

14 In the context of Risk Management, how is Risk typically calculated conceptually?

A.
B.
C.
D.

15 Which standard is specifically known as the Open Source Security Testing Methodology Manual?

A. OWASP
B. OSSTMM
C. ISO 27001
D. NIST SP 800-115

16 Why is Passive Reconnaissance preferred in the early stages of a stealthy penetration test?

A. It exploits vulnerabilities immediately
B. It relies on public information and does not alert the target's IDS/IPS
C. It generates a large amount of network traffic
D. It involves direct interaction with the target system

17 What is a critical Environmental Consideration when planning a penetration test on a SCADA or Industrial Control System (ICS)?

A. These systems handle high-speed video streaming
B. These systems are always connected to the internet
C. These systems are often fragile; active scanning may cause physical damage or safety hazards
D. These systems are usually robust and can handle heavy scanning traffic

18 Which US regulation requires healthcare organizations to secure Protected Health Information (PHI)?

A. GLBA
B. HIPAA
C. SOX
D. FISMA

19 During the Scoping phase, why is it important to identify Third-Party providers (e.g., Cloud hosts, ISPs)?

A. To obtain necessary permission, as testing their infrastructure without consent is illegal
B. To hack them instead of the client
C. To ensure they are ignored completely
D. To ask them for free software

20 What is the NIST Special Publication that acts as a Technical Guide to Information Security Testing and Assessment?

A. NIST SP 800-53
B. NIST SP 800-115
C. NIST SP 800-37
D. NIST SP 800-30

21 Which test type focuses on the human element of security?

A. Buffer Overflow
B. Social Engineering
C. Network Sniffing
D. SQL Injection

22 In the context of scoping, what is a Blackout Window?

A. The time when Black Box testing is conducted
B. A tool used to block network traffic
C. A period when the power is turned off
D. A specific time period where no testing is allowed due to critical business operations

23 What is the main advantage of an Internal penetration testing team?

A. They bring a completely unbiased external perspective
B. They have deep contextual knowledge of the organization's culture and systems
C. They are cheaper than automated tools
D. They do not require any rules of engagement

24 Which phase involves cleaning up artifacts, removing user accounts created during the test, and restoring settings?

A. Reconnaissance
B. Post-Exploitation / Restoration
C. Pre-engagement
D. Vulnerability Mapping

25 Which organization manages the Common Vulnerability Scoring System (CVSS)?

A. FIRST.org
B. FBI
C. Google
D. NSA

26 If a client requests a penetration test but forbids the use of automated scanners to prevent noise, this constraint is part of:

A. The CVSS score
B. The invoice
C. The Post-Mortem
D. The Rules of Engagement (RoE)

27 Which of the following is an example of Open Source Intelligence (OSINT)?

A. Scanning the target's firewall ports
B. Intercepting internal phone calls
C. Cracking the Wi-Fi password
D. Looking up employee email addresses on LinkedIn

28 What is the difference between Production and Staging environments in the context of scoping?

A. Production is live data; Staging is a replica for testing
B. There is no difference
C. Staging is more secure than Production
D. Production is for developers; Staging is for customers

29 Which legal concept requires the pentester to keep client findings secret?

A. Indemnification Clause
B. Non-Disclosure Agreement (NDA)
C. Chain of Custody
D. Statement of Work (SOW)

30 In the OWASP Top 10, what does OWASP stand for?

A. Online Wide Assessment of Security Procedures
B. Official Wireless Access Security Protocol
C. Organization for Web Authentication and Security Pentesters
D. Open Web Application Security Project

31 What is the primary goal of Physical Penetration Testing?

A. To ensure the website loads fast
B. To check if the air conditioning is working
C. To test the firewall throughput
D. To access the facility, server room, or workstations physically to compromise security

32 Which term describes a limitation where the tester cannot perform Denial of Service (DoS) attacks?

A. Compliance Failure
B. Rules of Engagement Constraint
C. Scope Creep
D. White Box Requirement

33 During the planning phase, defining Communication Paths ensures:

A. The tester can blog about the findings
B. The client knows who to contact if the test causes a critical outage
C. The media is informed of the test
D. The tester can ask the client for passwords

34 What is Scope Creep?

A. A method of physical entry
B. The gradual expansion of the project's goals or boundaries beyond the original agreement
C. A type of slow network scan
D. The process of analyzing results

35 Which testing methodology focuses heavily on the business logic and data flow?

A. Network Layer Testing
B. Physical Testing
C. Application Logic Testing
D. Wireless Testing

36 ISO/IEC 27001 is a standard for:

A. Medical Record Storage
B. Wireless Encryption
C. Payment Card Processing
D. Information Security Management Systems (ISMS)

37 In a Double-Blind test:

A. The tester knows nothing, and the client's security team is unaware of the test
B. The test is done twice
C. Both the tester and the client know everything
D. Two testers work simultaneously

38 What is the Statement of Work (SOW)?

A. A formal document defining the timeline, deliverables, and payment for the project
B. A code snippet used for exploitation
C. A list of vulnerabilities found
D. A manual for the testing software

39 If a pentester discovers evidence of a previous, ongoing criminal compromise during a test, what should they do?

A. Include it in the final report next month
B. Stop the test immediately and notify the client's point of contact
C. Hack the criminal back
D. Delete the evidence to clean the system

40 Which of the following is an example of Active Reconnaissance?

A. Port scanning using Nmap
B. Reading employee blogs
C. Searching WHOIS records
D. Browsing the company website

41 What does FEDRAMP standardize?

A. Security assessment and authorization for cloud products used by US federal agencies
B. European data privacy
C. Password complexity rules
D. Credit Card processing fees

42 Which scanning type identifies open ports and services?

A. Social Engineering
B. Port Scanning
C. Phishing
D. Vulnerability Scanning

43 In the context of the Cyber Kill Chain, which phase corresponds to the actual execution of malicious code on the target?

A. Weaponization
B. Exploitation
C. Actions on Objectives
D. Reconnaissance

44 Why is Shodan a relevant tool in the planning phase?

A. It is a search engine for Internet-connected devices
B. It cracks passwords
C. It is a virus scanner
D. It generates reports

45 What is Lateral Movement?

A. Moving deeper into a network from a compromised host to access other resources
B. Escalating privileges on a single machine
C. Exfiltrating data out of the network
D. Moving physically from one office to another

46 A Targeted Testing approach generally means:

A. Testing without any authorization
B. The IT team and the pentester work together to test a specific system
C. Testing only on weekends
D. Random testing of all systems

47 Which of the following represents a Technical constraint in scoping?

A. Legal restrictions
B. Holiday schedules
C. Bandwidth limitations or unstable network connections
D. Budget limitations

48 What is the primary focus of GDPR compliance testing?

A. Protecting the privacy and personal data of EU citizens
B. Securing medical devices
C. Protecting US Government Data
D. Ensuring credit card transactions are fast

49 When is the Chain of Custody relevant in penetration testing?

A. When ordering lunch
B. When writing the invoice
C. When handling physical evidence or forensic data found during a test
D. When scheduling the test

50 Mathematically, in the CVSS v3.1 equations, the Base Score is a function of:

A.
B.
C.
D.