CompTIA PenTest+ (PT0-003)Engagement ManagementMedium
A hospital hires a penetration testing firm specifically to demonstrate adherence to HIPAA Security Rule requirements ahead of an annual audit. The SOW requires the tester to validate a predefined checklist of technical safeguards rather than freely explore the environment for creative attack paths. This engagement is best classified as which type of assessment?
- AGoals-based assessment
- BBug bounty assessment
- CCompliance-based assessment
- DRed team assessment
Show answer & explanationAnswer & explanation
Correct answer: C. Compliance-based assessment
A compliance-based assessment is driven by a regulatory framework's specific checklist of controls, focusing on verifying required safeguards rather than open-ended objective attainment. A goals-based assessment instead targets a specific business objective (e.g., 'obtain domain admin'), and red team or bug bounty engagements emphasize broad, realistic attack simulation rather than checklist verification.
Why the other options are wrong
- A. Focuses on achieving a defined objective, not verifying a regulatory checklist.
- B. Crowdsourced, ongoing vulnerability discovery program, not a compliance-driven test.
- D. Emphasizes stealth and broad objective-based attack simulation, not compliance checklists.
Compliance-Based Assessment
A penetration test driven primarily by the need to satisfy a regulatory or contractual framework's specific checklist of required controls.
- Common drivers include HIPAA, PCI DSS, and SOX
- Scope is often narrower and checklist-driven
- Contrasts with goals-based or objective-driven testing
Memory trick: Compliance = Checklist; Goals = Get the flag