Multiple choice technology security

What is the first and most important thing an administrator should do prior to beginning a penetration test?

  1. Enable all necessary monitoring systems to track the test.

  2. Obtain all necessary permission to perform the test

  3. Identify system weaknesses

  4. Create a test plan

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Before conducting any penetration test, obtaining explicit written permission from system owners is not just a best practice - it's a legal and ethical requirement. Unauthorized penetration testing, even for benevolent purposes, is illegal. Monitoring systems (A), creating test plans (D), and identifying weaknesses (C) all come AFTER securing proper authorization. Permission protects both the tester and the organization.