Study. uk . com
  1. Home
  2. All questions
  3. Question 382

CISSP study material · question 382 of 500

A client asks what technical work happens during the planning phase of a penetration test. What does SP 800-115 say?

  1. None: planning is where rules are identified, management approval is documented and goals are set.
  2. Vulnerability scanning, so that the attack phase can begin immediately.
  3. Passive reconnaissance only, with no packets sent to the target.
  4. Baseline configuration review, to establish what should be present.
Show the answer

Answer: A. None: planning is where rules are identified, management approval is documented and goals are set.

SP 800-115 states that in the planning phase rules are identified, management approval is finalised and documented, and testing goals are set, and that no actual testing occurs.

Source: NIST SP 800-115 (NIST) — SP 800-115 > 5.2.1 Penetration Testing Phases

Challenge yourself on this topic → Study as cards