CERTIFICATION EXAM WITH QUESTIONS
AND VERIFIED ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1. Engagement Management
A penetration-testing firm has been contracted to assess a multinational
organization's external web infrastructure. The client provides the tester
with several IP addresses and domains but explicitly excludes all third-
party cloud infrastructure. During reconnaissance, the tester discovers
that one of the in-scope domains resolves to an IP address hosted by a
cloud provider. Which action should the penetration tester take FIRST
before conducting active testing against that IP?
A. Begin vulnerability scanning because the domain itself is in scope
B. Contact the cloud provider directly and request permission
C. Verify the asset's ownership and authorization status with the client
D. Perform exploitation only against low-risk vulnerabilities
E. Add the IP address to the scope because DNS maps the domain to it
Answer: C. Verify the asset's ownership and authorization status
with the client
Rationale: Scope is determined by explicit authorization, not merely by
DNS resolution. A domain resolving to third-party infrastructure does
not automatically authorize testing of that infrastructure. The tester
should verify ownership, authorization, and scope with the client
before sending potentially intrusive traffic.
1
,2. Engagement Management
A penetration test is scheduled from 22:00 to 04:00 on weekdays. At
23:30, the tester discovers a critical vulnerability that could potentially
cause a denial-of-service condition if exploited. The rules of engagement
state that denial-of-service testing is prohibited unless explicitly
approved by the client. What should the tester do?
A. Exploit it because the vulnerability is critical
B. Exploit it because the testing window is currently active
C. Ignore the vulnerability completely
D. Document the finding and follow the defined escalation process
E. Exploit it using a less aggressive payload without notification
Answer: D. Document the finding and follow the defined escalation
process
Rationale: A penetration test must remain within the agreed rules of
engagement. The criticality of a vulnerability does not override an
explicit prohibition. The tester should preserve evidence, document the
finding, and escalate according to the approved communication
procedure.
3. Engagement Management
A client wants a penetration test designed to simulate an attacker who
has no prior knowledge of the organization's infrastructure. The client
will provide only the organization's legal name and public-facing
domain. Which testing approach BEST matches this requirement?
A. White-box testing
B. Gray-box testing
C. Black-box testing
D. Credentialed testing
E. Cooperative testing
2
,Answer: C. Black-box testing
Rationale: Black-box testing simulates an attacker with little or no
internal knowledge of the target. White-box testing provides
substantial internal information, while gray-box testing provides
partial information or credentials.
4. Engagement Management
A penetration-testing engagement involves a web application that
processes payment-card information. The client asks the tester to include
payment-processing functionality in the assessment. Which
consideration is MOST important before testing begins?
A. Whether the application uses JavaScript
B. Whether applicable regulatory and contractual requirements permit
the planned testing
C. Whether the tester prefers authenticated scanning
D. Whether the application has a graphical user interface
E. Whether the tester can perform DNS enumeration
Answer: B. Whether applicable regulatory and contractual
requirements permit the planned testing
Rationale: Systems handling regulated or contractually protected
information can introduce additional legal, regulatory, privacy, and
contractual constraints. These requirements should be considered
during scoping and rules-of-engagement development.
5. Engagement Management
A penetration tester discovers a vulnerability that was not explicitly
included in the original statement of work. Exploiting the vulnerability
3
, would require interacting with a production database. What is the BEST
course of action?
A. Exploit it immediately because discovering it proves authorization
B. Exploit it only if the vulnerability has a CVSS score above 9.0
C. Obtain appropriate authorization before expanding the testing activity
D. Ask another tester to exploit it instead
E. Perform exploitation anonymously
Answer: C. Obtain appropriate authorization before expanding the
testing activity
Rationale: Discovery does not automatically authorize exploitation.
Expanding the scope of a penetration test—especially into a sensitive
production system—requires documented approval and appropriate
coordination.
6. Engagement Management
A penetration-testing report contains evidence showing that an
administrative account could access sensitive customer records. The
technical team understands the vulnerability, but senior executives need
to understand why the finding matters to the organization. Which report
element should BEST communicate this information?
A. Packet capture
B. Technical appendix
C. Executive summary
D. Tool configuration
E. Raw scanner output
Answer: C. Executive summary
Rationale: The executive summary translates technical findings into
business-level risk, impact, and overall security posture. Detailed
evidence belongs in the technical findings and supporting sections.
4