PENETRATION TESTING AND VULNERABILITY
ANALYSIS - D332 (PENTEST+ PTO-002) WGU LATEST
UPDATE 2025!!
Pre-Engagement Activities - DETAILED ANSWER -basic tasks that set the stage for a successful
penetration test
HIPPA - DETAILED ANSWER -regulates the confidentiality and security of healthcare information
in the US
GDPR - DETAILED ANSWER -imposes strict rules on data processing and movement within the
EU and for businesses or companies dealing with EU citizens' data
GLBA - DETAILED ANSWER -Plays an important role in protecting the privacy of individuals
financial information held by financial institutions
PCI DSS - DETAILED ANSWER -a globally recognized security standard designed to protect
cardholder data and reduce the risk of fraud in payment card transactions
ISO/IEC 27000 - DETAILED ANSWER -provides specifications for implementing, maintaining and
improving information security management systems
Stakeholder Alignment - DETAILED ANSWER -ensures that everyone from technical teams to
executive leadership understands the objectives and outcomes of a penetration test Regulations
,- DETAILED ANSWER -legally binding mandates which demand strict adherence to data
protection rules
Standards - DETAILED ANSWER -established by all of the important industry players embodying
the collective knowledge of best practices for cyber security
Network (Assessment) - DETAILED ANSWER -crucial for evaluating the security of an
organizations entire network as a whole
Things included in assessment
Network topology firewall
config security policies
Wireless (Assessment) - DETAILED ANSWER -focus on the security of wireless networks
Application (Assessment) - DETAILED ANSWER -Target the security of specific
applications whether developed in house or acquired from third parties This include
scrutinize application code, dependencies and configs
Mobile (Assessment) - DETAILED ANSWER -focus on mobile application and platforms and
evaluate security aspects such as data leaks, improper session handling and insecure data
storage
Web (Assessment) - DETAILED ANSWER -scrutinize web applications and websites for
vulnerabilities such as SQL injection cross site scripting and security misconfigurations Cloud
(Assessment) - DETAILED ANSWER -evaluate the security posture of cloud based services and
infrastructure
API (Assessment) - DETAILED ANSWER -focus on the security of application programming
interfaces which are critical for the integration of different software systems and services
,NDA - DETAILED ANSWER -An agreement that is designed to prohibit personnel from sharing
proprietary data. It can be used with employees within the organization and with other
organizations.
Master Service Agreement (MSA) - DETAILED ANSWER -set the foundational terms of the
business relationship between a service provider and the client
statement of work - DETAILED ANSWER -details the specifics of the project or service provided it
outlines the objectives deliverables scope of work timelines payment schedule and
responsibilities of each party
terms of service - DETAILED ANSWER -governs the use of the service provided by the pentest
firm
authorization letters - DETAILED ANSWER -essential for formally granting permission to the
penetration testing team to conduct simulated cyberattacks against the organizations systems
mandatory reporting requirements - DETAILED ANSWER -a critical aspect of pen testing that
dictate how and when findings must be disclosed
risks to pentesters - DETAILED ANSWER -Penetration testing involves probing and exploiting
security vulnerabilities which can lead to unintended consequences
establish escalation path - DETAILED ANSWER -should clearly outline the chain of command and
communication protocols
Rules of Engagement - DETAILED ANSWER -the rules that govern how pentests are conducted
, test cases - DETAILED ANSWER -predefined scenarios developed by the penetration testing team
to systematically evaluate the security of the system
testing window - DETAILED ANSWER -refers to the specific timeframe agreed upon by both
parties during which the pen test activities will occur
Goal reprioritization - DETAILED ANSWER -allows for changes in the tests priorities it
acknowledges that pentesting is a dynamic process
Business Impact Analysis (BIA) - DETAILED ANSWER -conducted to assess the potential
consequences for the client if the vulnerabilities identified during the pen test can be exploited
by a malicious actor
exclusions - DETAILED ANSWER -specifically designed areas or elements within the scope of the
pen test that are off limits
Classless Inter-Domain Routing (CIDR) (target selection) - DETAILED ANSWER -method used to
allocate IP addresses and route internet traffic, this defends the block of addresses used during
test
domains (target selection) - DETAILED ANSWER -human readable addresses used to access
websites on the internet and they play important role in external pen testing
IP (target selection) - DETAILED ANSWER -represent specific nodes or servers within a network
or on the internet
URL (target selection) - DETAILED ANSWER -point to specific resources on the internet or an
internal network often directing traffic to particular pages or services within a domain
ANALYSIS - D332 (PENTEST+ PTO-002) WGU LATEST
UPDATE 2025!!
Pre-Engagement Activities - DETAILED ANSWER -basic tasks that set the stage for a successful
penetration test
HIPPA - DETAILED ANSWER -regulates the confidentiality and security of healthcare information
in the US
GDPR - DETAILED ANSWER -imposes strict rules on data processing and movement within the
EU and for businesses or companies dealing with EU citizens' data
GLBA - DETAILED ANSWER -Plays an important role in protecting the privacy of individuals
financial information held by financial institutions
PCI DSS - DETAILED ANSWER -a globally recognized security standard designed to protect
cardholder data and reduce the risk of fraud in payment card transactions
ISO/IEC 27000 - DETAILED ANSWER -provides specifications for implementing, maintaining and
improving information security management systems
Stakeholder Alignment - DETAILED ANSWER -ensures that everyone from technical teams to
executive leadership understands the objectives and outcomes of a penetration test Regulations
,- DETAILED ANSWER -legally binding mandates which demand strict adherence to data
protection rules
Standards - DETAILED ANSWER -established by all of the important industry players embodying
the collective knowledge of best practices for cyber security
Network (Assessment) - DETAILED ANSWER -crucial for evaluating the security of an
organizations entire network as a whole
Things included in assessment
Network topology firewall
config security policies
Wireless (Assessment) - DETAILED ANSWER -focus on the security of wireless networks
Application (Assessment) - DETAILED ANSWER -Target the security of specific
applications whether developed in house or acquired from third parties This include
scrutinize application code, dependencies and configs
Mobile (Assessment) - DETAILED ANSWER -focus on mobile application and platforms and
evaluate security aspects such as data leaks, improper session handling and insecure data
storage
Web (Assessment) - DETAILED ANSWER -scrutinize web applications and websites for
vulnerabilities such as SQL injection cross site scripting and security misconfigurations Cloud
(Assessment) - DETAILED ANSWER -evaluate the security posture of cloud based services and
infrastructure
API (Assessment) - DETAILED ANSWER -focus on the security of application programming
interfaces which are critical for the integration of different software systems and services
,NDA - DETAILED ANSWER -An agreement that is designed to prohibit personnel from sharing
proprietary data. It can be used with employees within the organization and with other
organizations.
Master Service Agreement (MSA) - DETAILED ANSWER -set the foundational terms of the
business relationship between a service provider and the client
statement of work - DETAILED ANSWER -details the specifics of the project or service provided it
outlines the objectives deliverables scope of work timelines payment schedule and
responsibilities of each party
terms of service - DETAILED ANSWER -governs the use of the service provided by the pentest
firm
authorization letters - DETAILED ANSWER -essential for formally granting permission to the
penetration testing team to conduct simulated cyberattacks against the organizations systems
mandatory reporting requirements - DETAILED ANSWER -a critical aspect of pen testing that
dictate how and when findings must be disclosed
risks to pentesters - DETAILED ANSWER -Penetration testing involves probing and exploiting
security vulnerabilities which can lead to unintended consequences
establish escalation path - DETAILED ANSWER -should clearly outline the chain of command and
communication protocols
Rules of Engagement - DETAILED ANSWER -the rules that govern how pentests are conducted
, test cases - DETAILED ANSWER -predefined scenarios developed by the penetration testing team
to systematically evaluate the security of the system
testing window - DETAILED ANSWER -refers to the specific timeframe agreed upon by both
parties during which the pen test activities will occur
Goal reprioritization - DETAILED ANSWER -allows for changes in the tests priorities it
acknowledges that pentesting is a dynamic process
Business Impact Analysis (BIA) - DETAILED ANSWER -conducted to assess the potential
consequences for the client if the vulnerabilities identified during the pen test can be exploited
by a malicious actor
exclusions - DETAILED ANSWER -specifically designed areas or elements within the scope of the
pen test that are off limits
Classless Inter-Domain Routing (CIDR) (target selection) - DETAILED ANSWER -method used to
allocate IP addresses and route internet traffic, this defends the block of addresses used during
test
domains (target selection) - DETAILED ANSWER -human readable addresses used to access
websites on the internet and they play important role in external pen testing
IP (target selection) - DETAILED ANSWER -represent specific nodes or servers within a network
or on the internet
URL (target selection) - DETAILED ANSWER -point to specific resources on the internet or an
internal network often directing traffic to particular pages or services within a domain