CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 523


Which of the following should be done FIRST when planning a penetration test?

Show Answer
Correct Answer: AC

The first step in planning a penetration test is to define the testing scope. Defining the scope is crucial as it outlines the boundaries, objectives, and limitations of the penetration test. This includes determining what systems, networks, applications, or assets will be included in the test and specifying the goals and targets of the assessment. Without a clearly defined scope, it is impossible to plan the test effectively or obtain meaningful consent from management. Once the scope is defined, other steps, including obtaining management consent and determining reporting requirements, can follow.

Discussion

8 comments
Sign in to comment
saado9Option: A
Apr 28, 2023

Must be A. Define testing scope

ItsBananass
Jun 29, 2023

Are you going to plan for something you don't have approval for?

AliHamza
Jul 3, 2023

If there is no scope then what management will approve?

Yejide03
Feb 5, 2024

Sorry I’m going for A

RachyOption: A
Jan 19, 2024

You write a memo of what you want to do first before approval. Definition of scope come first so A is the answer

Rachy
Jan 19, 2024

I change my answer to C. According to CRM, chapter 5 page 335, it is imperative to obtain Management’s consent in writing before finalization of the test/ engagement scope. The chosen answer C is correct

RachyOption: C
Jan 19, 2024

I change my answer to C. According to CRM, chapter 5 page 335, it is imperative to obtain Management’s consent in writing before finalization of the test/ engagement scope. The chosen answer C is correct

hohoOption: A
May 17, 2023

Agree, First step should be Scope, management consent follow

JolomsOption: A
Jun 29, 2023

tHE ANSWER IS a https://www.imperva.com/learn/application-security/penetration-testing/#:~:text=The%20first%20stage%20involves%3A,works%20and%20its%20potential%20vulnerabilities.

FemduOption: A
Jul 20, 2023

The scope should be stated in the approval. Hence, scope definition comes first!

3008Option: A
Aug 11, 2023

A is answer.

SwallowsOption: A
Jun 9, 2024

Defining the testing scope is crucial as it outlines the boundaries, objectives, and limitations of the penetration test. It helps determine what systems, networks, applications, or assets will be included in the test and specifies the goals and targets of the assessment. Additionally, defining the scope ensures that the penetration test focuses on areas of highest risk or concern to the organization, aligns with business objectives, and meets regulatory requirements. Once the testing scope is established, the organization can proceed with obtaining management consent for the testing (Option C). Management consent is essential to ensure that stakeholders are aware of the planned activities, potential impacts, and expected outcomes of the penetration test. However, without a clearly defined testing scope, it may be challenging to obtain informed consent from management.