SY0-701 Question 451
Single answerRules of engagementA company hires a third-party security firm to perform a penetration test against its production environment. During the kickoff meeting, the company's legal team says customer-facing systems must remain available during business hours, the network team says testing should not originate from certain countries because of geofencing controls, and the SOC manager wants to be notified immediately if the testers discover active malware or a critical exposure. Which document should define these boundaries, communication requirements, and constraints before testing begins?
- A
Rules of engagement
- B
Service-level agreement
- C
Nondisclosure agreement
- D
Incident response playbook
Show answer and explanation
Correct answer: A
Explanation
Rules of engagement are a foundational part of authorized security testing. They help ensure the test is legally authorized, operationally safe, and aligned with business requirements. In practice, the RoE commonly documents scope, permitted and prohibited activities, target systems, testing windows, source IPs or geographic restrictions, points of contact, escalation procedures, evidence handling, and stop-test conditions. These items are especially important for production assessments where unplanned disruption could affect customers. Industry best practices for penetration testing and red-team activities commonly emphasize documenting scope and authorization up front, including communication paths and restrictions, before any testing begins. This aligns with standard guidance from professional penetration testing methodologies and common enterprise security governance practices.
- A. Correct.
Correct. The rules of engagement (RoE) document defines the authorized scope, test boundaries, timing restrictions, permitted techniques, communication and escalation paths, and conditions for stopping or pausing testing. In this scenario, business-hour restrictions, prohibited source locations, and immediate notification requirements are classic RoE elements that must be agreed upon before a penetration test starts.
- B. Incorrect.
Incorrect. A service-level agreement (SLA) defines expected service performance and support metrics, such as uptime targets or response times between parties. While an SLA may exist between the customer and the security firm, it does not typically establish operational testing boundaries such as approved targets, prohibited actions, escalation triggers, or hours of testing.
- C. Incorrect.
Incorrect. A nondisclosure agreement (NDA) is used to protect confidential information shared during the engagement. It is important for handling sensitive findings, credentials, and internal details, but it does not specify how the test will be conducted, what systems are in scope, or when the SOC must be notified.
- D. Incorrect.
Incorrect. An incident response playbook provides procedural guidance for responding to specific security incidents. Although the SOC may rely on playbooks if the test triggers alerts or uncovers malware, the playbook is not the document used to define the pentest's preapproved scope, constraints, and communication rules.