When designing a comprehensive and professional penetration testing plan for a critical production environment, why is it critical to explicitly separate the initial network discovery phase from subsequent service version checking and vulnerability exploitation phases?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ADiscovery typically needs no special credentials, and credentialed testing is often more relevant to later phases, so this reasoning is backwards.
- BCorrect: host discovery is lightweight, while intrusive version probes and exploitation can crash fragile services, so separating them lets each risk be approved and scheduled.
- CExploitation can be scoped from external or internal positions depending on the engagement; no rule requires internal segments.
- DVersion checks do not trigger automatic legal notices to ISPs; authorization comes from the engagement contract, not from scan behavior.