CompTIA PenTest+ (PT0-003)Engagement ManagementMedium
A penetration tester's Rules of Engagement specify that all active scanning and exploitation must occur only between 20:00 and 06:00 to avoid disrupting production systems. At 14:00, while reviewing earlier reconnaissance data, the tester identifies a critical remote code execution vulnerability that could be exploited immediately with Metasploit. What should the tester do?
- AImmediately exploit the vulnerability since it is critical and delay could increase risk
- BDocument the finding and wait until the authorized testing window to attempt exploitation
- CDiscard the finding since it was identified outside the approved window
- DExploit it now but notify the client afterward to stay ahead of real attackers
Show answer & explanationAnswer & explanation
Correct answer: B. Document the finding and wait until the authorized testing window to attempt exploitation
The RoE is a binding agreement; testers must adhere to approved testing windows regardless of finding severity, unless an emergency change is explicitly negotiated with the client. The correct action is to document the finding and act within authorized hours.
Why the other options are wrong
- A. Violates RoE and could cause unauthorized impact during business hours.
- C. Findings should never be discarded; they still must be reported and acted on properly.
- D. Still violates RoE; notifying afterward doesn't excuse unauthorized action.
Rules of Engagement (RoE)
A document specifying the technical constraints of a penetration test, including timing, methods, and systems allowed.
- Includes approved testing windows/blackout periods
- Defines permitted techniques and tools
- Legally binding — deviations require client approval
Memory trick: RoE = 'Rules Over Everything' during testing