Kizspy | Question: 44
(Choose 1 answer)
A company hires a cybersecurity consultant to perform penetration tests and review the rules of engagement
documents. The consultant notices that one element specifies that the tests should be performed toward only
web applications on websites www1.company.com and www2.company.com, with no social engineering
attacks and no cross-site scripting attacks. Which element in the document is used for the specification?
A. location of testing
B. types of allowed or disallowed tests
C. IP addresses or networks from which testing will originate
D. the security controls that could potentially detect or prevent testing