CompTIA PenTest+ (PT0-003)Engagement ManagementHard

A penetration test's scope includes a web application hosted on a third-party cloud provider's infrastructure. Before launching active Burp Suite scans against the application's endpoints, what additional step MUST the tester verify has been completed?

  1. AThe hashcat licensing terms permit testing against cloud-hosted assets
  2. BOnly the signed SOW between the tester and client is sufficient
  3. CThe client's internal change management board has approved the testing dates
  4. DThe cloud provider's third-party penetration testing policy and required authorization have been satisfied
Show answer & explanation

Correct answer: D. The cloud provider's third-party penetration testing policy and required authorization have been satisfied

Most cloud providers (e.g., AWS, Azure, GCP) require separate authorization or notification before penetration testing occurs on infrastructure they host, since testing could affect shared resources or violate the provider's acceptable use policy. Client authorization alone is not sufficient for cloud-hosted assets.

Why the other options are wrong

  • A. hashcat is a password-cracking tool unrelated to cloud testing authorization.
  • B. The SOW covers the client relationship but not the third-party cloud provider's separate requirements.
  • C. Internal change management is useful but doesn't satisfy the cloud provider's own testing policy.

Third-Party Cloud Testing Authorization

The requirement to obtain separate approval from a cloud service provider before conducting penetration tests on infrastructure they host, in addition to client authorization.

  • Cloud providers (AWS, Azure, GCP) have specific testing policies
  • Failure to comply can violate provider ToS and cause legal issues
  • Client's SOW/RoE alone does not authorize testing of third-party infrastructure

Memory trick: Cloud = someone else's server, so ask them too!

More Engagement Management questions