adplus-dvertising
frame-decoration

Question

What is scope creep in the context of penetration tests?

a.

The intentional expansion of the target scope

b.

The addition of more items and targets to the scope

c.

The exclusion of important targets from the scope

d.

The modification of the scoping document

Answer: (b).The addition of more items and targets to the scope Explanation:Scope creep in the context of penetration tests refers to the addition of more items and targets to the scope of the assessment, which can lead to unplanned expansions during the assessment.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. What is scope creep in the context of penetration tests?

Similar Questions

Discover Related MCQs

Q. What is the recommended action to handle scope creep during a penetration test?

Q. How can internal knowledgebase articles support penetration testers?

Q. What information can be found in configuration files that is valuable for penetration testers?

Q. Why is understanding the use of software development kits (SDKs) important for penetration testers?

Q. What is a common security exception for known environment tests?

Q. What does certificate pinning associate a host with?

Q. What role does access to user accounts and privileged accounts play in penetration tests?

Q. What is one of the most powerful tools a penetration tester can have?

Q. Why is network access important for penetration testers?

Q. What determines the budget required for a penetration test?

Q. For external or commercial testers, what might the budget for a penetration test include?

Q. Which framework provides a knowledgebase of adversary tactics and techniques, including details of mitigations, threat actor groups, and software?

Q. What does the Open Web Application Security Project (OWASP) provide guides for?

Q. Which penetration testing standard covers pre-engagement interactions, scoping, and details such as dealing with third parties?

Q. What does the MITRE ATT&CK Framework stand for?

Q. What should be considered when using dated penetration testing standards?

Q. Which penetration testing methodology guide covers analysis, metrics, workflows, human security, physical security, and wireless security but has not been updated since 2010?

Q. Which organization provides standards that include penetration testing as part of NIST special publication 800-115?

Q. What is the last update year for the Information Systems Security Assessment Framework (ISSAF)?

Q. What should modern penetration testers be aware of regarding the ISSAF?