Subdomain 1.1: Planning and scoping
1.During scoping calls for a web application assessment, the client provides a single production URL and states that a staging environment exists on a different subdomain but should not be tested because it contains synthetic data unrelated to the engagement's goals. Which scoping activity does this exchange represent?
- A.Target selection, since the parties are agreeing on which URLs and hosts fall inside versus outside the assessment
- B.Shared responsibility mapping, since the parties are dividing security duties between the hosting provider and the client
- C.Agreement type selection, since the parties are choosing between an NDA, MSA, or SoW to govern the engagement
- D.Testing framework alignment, since the parties are agreeing to follow PTES or OSSTMM methodology for the assessment
Show answer & explanation
Correct answer: A — Target selection, since the parties are agreeing on which URLs and hosts fall inside versus outside the assessment
- A. Target selection is correct because the client is explicitly identifying which URL is in scope and which subdomain is excluded, which is the definition of choosing the domains, IPs, or URLs to be tested.
- B. Shared responsibility mapping concerns who owns which security control between hosting provider, customer, and tester, not which hostnames get tested, so it does not describe this conversation.
- C. Agreement type selection covers legal documents like NDAs or SoWs that govern the engagement contractually, not the technical decision about which hosts are in or out of scope.
- D. Testing framework alignment refers to choosing a methodology such as PTES to structure the assessment, which is unrelated to deciding which subdomain gets excluded from testing.