1.0Engagement Management
13%48 practice questions in this domain
- 1.1Summarize pre-engagement activities (scope definition, rules of engagement, agreement types, target selection, assessment types, shared responsibility model, legal and ethical considerations)
- 1.2Explain collaboration and communication activities (peer review, stakeholder alignment, escalation path, articulation of risk, business impact analysis, client acceptance)
- 1.3Compare and contrast testing frameworks and methodologies (OSSTMM, CREST, PTES, MITRE ATT&CK, OWASP Top 10, OWASP MASVS, Purdue model, DREAD, STRIDE, OCTAVE)
- 1.4Explain the components of a penetration test report (format alignment, report components, test limitations and assumptions, reporting considerations)
- 1.5Given a scenario, analyze the findings and recommend the appropriate remediation within a report (technical, administrative, operational, and physical controls)