CompTIA PenTest+ (PT0-003)Engagement ManagementEasy
A penetration tester is performing an on-site physical security assessment. While attempting to badge into a server room, the tester is confronted by building security, who calls the local police. What should the tester immediately provide to avoid being arrested?
- AA copy of the SOW listing billing rates
- BA copy of the signed NDA
- CA copy of the signed authorization letter (permission-to-test document)
- DA copy of the OSSTMM RAV calculation worksheet
Show answer & explanationAnswer & explanation
Correct answer: C. A copy of the signed authorization letter (permission-to-test document)
An authorization letter, often called a 'get-out-of-jail-free card,' is signed by the client and carried by testers to prove they have legal permission to conduct the assessment. Presenting it to law enforcement or security personnel demonstrates the activity is authorized and not criminal trespass or hacking.
Why the other options are wrong
- A. The SOW defines deliverables and cost, not proof of authorization for physical entry.
- B. The NDA covers confidentiality, not legal authorization to perform the test.
- D. An OSSTMM RAV score is a technical risk metric, irrelevant to legal authorization.
Authorization Letter
A signed document from the client granting explicit permission for specific testing activities, carried by testers as legal proof of authorization.
- Also called a 'get-out-of-jail-free card'
- Should be carried during on-site or physical engagements
- Distinct from the NDA, MSA, and SOW
Memory trick: NASOR: NDA, Authorization, SOW, MSA, RoE — each document plays a role.