exam questions

Exam PT0-001 All Questions

View all questions & answers for the PT0-001 exam

Exam PT0-001 topic 1 question 41 discussion

Actual exam question from CompTIA's PT0-001
Question #: 41
Topic #: 1
[All PT0-001 Questions]

Which of the following are MOST important when planning for an engagement? (Select TWO).

  • A. Goals/objectives
  • B. Architectural diagrams
  • C. Tolerance to impact
  • D. Storage time for a report
  • E. Company policies
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
xMilkyMan123
Highly Voted 4 years, 3 months ago
I think the wedding ring is most important for an engagement
upvoted 14 times
boyladdudeman
4 years, 1 month ago
This may be the reason your session attempts failed
upvoted 7 times
...
boyladdudeman
4 years, 1 month ago
You don't offer the wedding ring at an engagement, you offer the engagement ring.
upvoted 5 times
...
...
kloug
Most Recent 2 years, 2 months ago
a,e correct
upvoted 1 times
...
miabe
2 years, 9 months ago
Selected Answer: AC
looks good to me
upvoted 1 times
...
onikafei
3 years, 1 month ago
Selected Answer: AE
Im going with A and E. If I recall correctly goals/objectives and the company policies were kind of the big first steps when planning engagement. You have to really push through that stuff. a lot had to do with cost as well. C - I know will come up, but not in the beginning stages of engagement.
upvoted 1 times
...
DrChats
3 years, 4 months ago
A and C
upvoted 3 times
...
Ariel235788
3 years, 5 months ago
I still say C and E. When i think policies i think of things like NDAs. Obvs getting a NDA done would come before setting goals.
upvoted 1 times
...
SciBer
3 years, 6 months ago
A. and C. - The most important planning for engagement is to focus on the: "Goals/Objective" - this is what the client will set in the MSA or ROE, what they want you to test. "Tolerance" - depending on if you are testing their production or development network, will determine the tolerance they are will to accept in either environment.
upvoted 1 times
...
rose_y
3 years, 6 months ago
just make sure they're the right one for you first.
upvoted 1 times
...
CybeSecN
3 years, 9 months ago
I am going for A and C as it they make more sense.
upvoted 4 times
...
hnj11
4 years, 1 month ago
I believe its A and E.
upvoted 3 times
...
EZPASS
4 years, 4 months ago
I agree. A and C make the most sense here.
upvoted 2 times
...
someguy1393
4 years, 4 months ago
I'm going to go with A & C but I understand how E is also a viable option.
upvoted 2 times
...
byrne
4 years, 5 months ago
I'd go for A & C. Pentest Plan.- Goals/ Objectives 'Tolerance to impact' would be within Risk and Contingencies https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/planning-for-information-security-testinga-practical-approach
upvoted 3 times
...
boblee
4 years, 10 months ago
A and C. company policies is a general consideration.
upvoted 2 times
...
zeroes_n_ones
4 years, 11 months ago
Company policy may be part of the reason why pen testers are there too.
upvoted 1 times
...
D1960
4 years, 12 months ago
Company policy may be important in the *decision* as to whether, or not, you want to have a pentest. But it is not usually part of the planning process. Goals and objectives are always part of the planning process.
upvoted 2 times
...
mr_robot
5 years ago
PenTest+ Practice Tests Book C and E. - Knowing the company policies and their tolerance to impact are two of the most important items needed to know when planning for an engagement. The others are important, but this scenario is asking for the two most important. Cybersecurity professionals widely agree that vulnerability management is a critical component of any information security program, and for this reason, many organizations mandate vulnerability scanning in corporate policy, even if that is not a regulatory requirement. The risk and impact tolerance of the organization being assessed should be used to define the scope and rules of engagement for the assessment.
upvoted 3 times
TheThreatGuy
4 years, 3 months ago
Makes sense... Doesn't mean the others are wrong, this is just the MOST important... Company Policy would include any regulations that need to be met, and tolerance to impact would determine how detailed your pentest needs to be... Goals/Objectives would be defined based on those two answers, making it the "MOST important".
upvoted 1 times
TheThreatGuy
4 years, 3 months ago
I think I'm changing my mind on this..... Isn't part of a pentest to determine if the company policy is meeting expectations? With that it mind, I think goals/objectives and tolerance to impact would be the best answer here. That would determine your limitations as a pentester for this engagement.
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago