A company prepares to hire a vendor to perform a penetration test on the company ' s production systems. Which of the following should the company do first?
A.
Grant the test team administrative access rights.
B.
Monitor firewall logs to detect post-test anomalous activity.
C.
Obtain signed contracts detailing scope, liability, and rules of engagement.
D.
Ensure all findings are logged in the SIEM for correlation.
Before a penetration test begins, the organization must obtain signed contracts that define scope, liability, authorization, and rules of engagement. This protects both the company and the vendor by documenting exactly what systems may be tested, what techniques are allowed, what time windows apply, how findings will be handled, and who is responsible if disruption occurs. Granting administrative access before authorization is reckless and can create unnecessary risk. Monitoring firewall logs is useful during and after testing, but it is not the first step. Logging findings in the SIEM may help correlation, but findings are normally documented in the penetration test report. The first requirement is formal written authorization and agreed rules.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit