Lesson 2 - Defining the Rules of Engagement Flashcards
If you want to test your Internal IT Team what is the best assessment type to utilize
Red Team vs Blue Team
Adversary vs Defense
What is the best strategy if the client wants you to fully act like a Bad Actor
Unknown Environment - completely in Dark
T or F should the PenTest engagement review any non-security related items such as backups?
True - yes. these should all be addressed during the confirmation of the scope.
What is a requirement for avoiding liabilities during a PenTest Engagement
Must ensure Confidentiality based on local, state and Federal requirements such as:
Gramm-Leach-Biley Act (GLBA) requiring financial institutions
Drivers Privacy Protection Act - state DMV
HIPAA
What is the contract that establishes precedence and guidelines for any business documents that are executed between two parties
Master Services Agreement
If a party wants to see details on what is being performed, timeline, deliverables, and expectations of invoicing where would they find that
Scope of Work
What is the contract that sets the service requirements and PenTest Process
Service Level Agreement
processing requirements for confidential and private data