pt0 002 02
pt0 002 02
pt0 002 02
Exam PT0-002
Lesson 2
Defining the Rules of Engagement
3
Lesson 2
Topic 2A
Assess Environmental Considerations
5
Gather the Requirements
• Assess the LAN and the WLAN
• Evaluate web and/or mobile applications.
• Define guidelines, such as number of pages that require user interaction.
6
Define the In-Scope Assets
• The stakeholders will need to be specific as to what assets will be
included in the scope. Some example include:
• Internet Protocol (IP) addresses
• Domain and/or subdomains
• Application programming interfaces (APIs)
7
Determine Locations and Hosting Methods
• Identify the physical locations that are in-scope, and whether the
target is on-site or off-site.
• Other considerations:
• Whether the team will test external or internal assets
• Define how assets are hosted: First-Party and/or Third-Party
8
Restrictions that will influence testing
• Country, state, and local laws can impact testing.
• Can restrict the technology, tools and methods used during PenTesting
9
Review Activity: Assess Environmental Considerations
• Outline the importance of defining the Project Scope
• Discuss activities related to gathering the requirements
• Stress the importance of determining physical locations, and
whether testing is on-site or off-site.
• Explain how certain restrictions can influence PenTesting
10
Lesson 2
Topic 2B
Outline the Rules of Engagement
• Goals-based/objectives-based
16
Lesson 2
Topic 2C
Prepare Legal Documents
• The validity period of the authorization and proper data handling techniques
19
Master Service Agreement (MSA)
• A contract that governs all future transactions or future agreements
between the PenTesting team and the client
• Can be used to cover recurring costs and any unforeseen additional
charges without the need for an additional contract.
• Some of the elements should include details on the following:
• Project scope and a definition of the work to be completed
20
Outline the Statement of Work
• Defines the expectations for a
specific business arrangement.
• It typically includes:
• List of deliverables
• Responsibilities of both parties
• Payment milestones
• Schedules, and other terms.
21
Prepare the Service-Level Agreement
• Outlines the level of service expected
• Defines the metrics which that service is measured, and any remedies or
penalties should the agreed-on service levels not be achieved.
• May include terms for security access controls and risk assessments, along
with processing requirements for confidential and private data.
22
Review Activity: Prepare Legal Documents
• Review laws that require the confidentiality of data while testing
• List some of the information included in the documentation that
gives permission to attack
• Discuss the importance of the Master Service Agreement
• Describe what’s included in a Statement of Work
• Outline the components of a Service-Level Agreement
23
Lesson 2
Summary