CompTIA PenTest+ (PT0-003)Engagement ManagementMedium

A hospital hires a penetration testing firm specifically to demonstrate adherence to HIPAA Security Rule requirements ahead of an annual audit. The SOW requires the tester to validate a predefined checklist of technical safeguards rather than freely explore the environment for creative attack paths. This engagement is best classified as which type of assessment?

  1. AGoals-based assessment
  2. BBug bounty assessment
  3. CCompliance-based assessment
  4. DRed team assessment
Show answer & explanation

Correct answer: C. Compliance-based assessment

A compliance-based assessment is driven by a regulatory framework's specific checklist of controls, focusing on verifying required safeguards rather than open-ended objective attainment. A goals-based assessment instead targets a specific business objective (e.g., 'obtain domain admin'), and red team or bug bounty engagements emphasize broad, realistic attack simulation rather than checklist verification.

Why the other options are wrong

  • A. Focuses on achieving a defined objective, not verifying a regulatory checklist.
  • B. Crowdsourced, ongoing vulnerability discovery program, not a compliance-driven test.
  • D. Emphasizes stealth and broad objective-based attack simulation, not compliance checklists.

Compliance-Based Assessment

A penetration test driven primarily by the need to satisfy a regulatory or contractual framework's specific checklist of required controls.

  • Common drivers include HIPAA, PCI DSS, and SOX
  • Scope is often narrower and checklist-driven
  • Contrasts with goals-based or objective-driven testing

Memory trick: Compliance = Checklist; Goals = Get the flag

More Engagement Management questions