PenTest+ V2 Scope Creep and Change Control Quiz

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 8865 | Total Attempts: 106,055
| Questions: 20 | Updated: Aug 13, 2026
Please wait...
Question 1 / 21
🏆 Rank #--
0 %
0/100
Score 0/100

1. Rules of engagement in penetration testing specify ____.

Submit
Please wait...
About This Quiz
PenTest+ V2 Scope Creep and Change Control Quiz - Quiz

This quiz evaluates your understanding of scope management and change control in penetration testing engagements. Learn how to define project boundaries, identify scope creep risks, implement change control procedures, and maintain alignment between stakeholders and testing objectives. Essential knowledge for PenTest+ V2 certification and professional security assessment practices.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. When a client requests testing of a system not in the original scope, the tester should first ____.

Submit

3. What is the primary benefit of documenting all scope decisions and change approvals?

Submit

4. True or False: Penetration testers should test systems beyond the stated scope if they believe it will improve security.

Submit

5. A scope change requires impact analysis to assess ____.

Submit

6. Which element should be clearly defined to prevent scope creep?

Submit

7. True or False: Scope creep is beneficial because it allows testers to find more vulnerabilities and provide greater value.

Submit

8. A client requests adding 50 new systems to testing mid-engagement. The tester should ____.

Submit

9. Which of the following best describes the relationship between scope and project risk?

Submit

10. True or False: Testing production systems without explicit written scope approval is acceptable if the tester believes it is necessary.

Submit

11. What is the primary purpose of establishing clear scope boundaries in a penetration testing engagement?

Submit

12. A tester discovers a critical vulnerability in a system marked as out-of-scope. What should the tester do?

Submit

13. Which stakeholder role is typically responsible for approving scope changes during a penetration test?

Submit

14. True or False: Scope boundaries should remain completely static throughout the entire engagement, regardless of findings.

Submit

15. Out-of-scope systems are those that ____.

Submit

16. A change control process in penetration testing should include which elements?

Submit

17. What is the most important reason to obtain written authorization before beginning a penetration test?

Submit

18. True or False: A change request during an active penetration test should always be approved immediately to maximize testing coverage.

Submit

19. Which of the following is NOT a typical component of a penetration testing scope document?

Submit

20. Scope creep in penetration testing refers to ____.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (20)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
Rules of engagement in penetration testing specify ____.
When a client requests testing of a system not in the original scope,...
What is the primary benefit of documenting all scope decisions and...
True or False: Penetration testers should test systems beyond the...
A scope change requires impact analysis to assess ____.
Which element should be clearly defined to prevent scope creep?
True or False: Scope creep is beneficial because it allows testers to...
A client requests adding 50 new systems to testing mid-engagement. The...
Which of the following best describes the relationship between scope...
True or False: Testing production systems without explicit written...
What is the primary purpose of establishing clear scope boundaries in...
A tester discovers a critical vulnerability in a system marked as...
Which stakeholder role is typically responsible for approving scope...
True or False: Scope boundaries should remain completely static...
Out-of-scope systems are those that ____.
A change control process in penetration testing should include which...
What is the most important reason to obtain written authorization...
True or False: A change request during an active penetration test...
Which of the following is NOT a typical component of a penetration...
Scope creep in penetration testing refers to ____.
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!