exam questions

Exam PT0-001 All Questions

View all questions & answers for the PT0-001 exam

Exam PT0-001 topic 1 question 89 discussion

Actual exam question from CompTIA's PT0-001
Question #: 89
Topic #: 1
[All PT0-001 Questions]

A client asks a penetration tester to add more addresses to a test currently in progress. Which of the following would define the target list?

  • A. Rules of engagement
  • B. Mater services agreement
  • C. Statement of work
  • D. End-user license agreement
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
boblee
Highly Voted 4 years, 10 months ago
Statement of Work.
upvoted 13 times
...
mr_robot
Highly Voted 5 years ago
PenTest+ Practice Tests Book - SYBEX C. - A statement of work (SOW) defines what work will be done during an engagement. A SOW is a document that defines the purpose of the test, what tests will be done, what will be created, the timeline for the test to be completed, the price for the testing, and any additional terms and conditions.
upvoted 7 times
D1960
4 years, 11 months ago
Certainly seems reasonable. But according to the "All-in-One" CompTIA Pentest book. The RoE defines "the type and scope of testing."
upvoted 2 times
...
...
kloug
Most Recent 2 years, 2 months ago
AAAAAAAAAA
upvoted 1 times
...
miabe
2 years, 9 months ago
Selected Answer: A
looks good to me
upvoted 1 times
...
miabe
2 years, 9 months ago
Selected Answer: C
looks good to me
upvoted 1 times
...
contender
3 years, 4 months ago
SOW - States what will be tested ROE - How and when the testing will occur
upvoted 2 times
...
Ariel235788
3 years, 6 months ago
Statement of Work = Work to be done. RoE - Targets that are to be hit. Answer is A
upvoted 1 times
...
MrRiver
3 years, 7 months ago
Well, if you go throug the SANS Rules of Engagment Worksheet Only Attacker IP's are mentioned. https://sansorg.egnyte.com/dl/bF4I3yCcnt/? So i would go with the Statement of Work
upvoted 1 times
...
versun
3 years, 10 months ago
Answer is A ROE https://community.infosecinstitute.com/discussion/134877/rules-of-engagement-vs-sow
upvoted 2 times
...
nonyabiz
3 years, 10 months ago
Pay attention to the actual question fellas. This says "which of the following would define the target list?". They're throwing you off with that addition peice and your brain is going straight to scope creep. The question itself has NOTHING to do with scope creep. The question is a simple "where would this be defined" and it's definitely part of the ROE doc.
upvoted 2 times
...
RedbyNight
4 years, 2 months ago
I think this is actually a question about scope creep. If this was a real world scenario then the pen tester would need to know more about the new targets, which sort of swings the process round to the start. I'd say this would mean revisiting the statement of works
upvoted 2 times
...
TheThreatGuy
4 years, 3 months ago
I would say "both"... but since that isn't an answer... SoW defines the targets, RoE gives specifics on how you are going to attack the target. So C.
upvoted 1 times
...
goldengodiva
4 years, 4 months ago
The rules of engagement are established BEFORE testing begins and are usually not modified. If the test has begun and new requirements are added, they will be included in the SOW. So I think the answer is C.
upvoted 1 times
...
harej8
4 years, 11 months ago
A - Rules of Engagement – This is the meat of the document, and these rules are crucial to reveal in detail, as they provide the dos and do nots of testing. They contain a lot of important project specifics such as special testing parameters, requested rules the testing team should abide by, and disclosures about testing that can help protect the client. Below are some of the different things captured and detailed in this section: Treatment of sensitive information during the project How project status updates will be communicated Emergency contact information Handling of a sensitive and critical vulnerability Steps taken if a prior compromise is uncovered Security controls impact and specifics IP addresses of testing machines for monitoring/whitelisting Requirements for third-party hosting provider approvals to test In-scope targets, including the IP addresses and URLs Any specific compromise goals (i.e. Material and Non-public information, Credit Card Data) Specific web-forms to be avoided
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago